Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
碩士 === 中原大學 === 電機工程研究所 === 91 === Abstract In this thesis, we propose four new authentication protocols for Single-Realm and Cross-Realm Authentications based on multiple Kerberi authentication technique. Single-Realm authentication is used when user is in the home area. Cross-Realm authentication...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2003
|
Online Access: | http://ndltd.ncl.edu.tw/handle/s369np |
id |
ndltd-TW-091CYCU5442012 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-091CYCU54420122018-06-25T06:06:26Z http://ndltd.ncl.edu.tw/handle/s369np Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) 以多重Kerberos建構無線區域網路之全域認證 Yu-Hung Lai 賴昱宏 碩士 中原大學 電機工程研究所 91 Abstract In this thesis, we propose four new authentication protocols for Single-Realm and Cross-Realm Authentications based on multiple Kerberi authentication technique. Single-Realm authentication is used when user is in the home area. Cross-Realm authentication with multiple Kerberi protocols achieves the goal that users roam anytime around worldwide. The roaming user can be authenticated in the visit area by his home authentication server (AS). Additionally, because of insecure feature of symmetric cryptosystems, we adopt public key cryptosystems to realize the proposed protocols. In the first and third proposed protocols, the actions for user authenticates with access point (AP) is reduced to speed up the authentication time. At first, AS receives the identity from the user and forwards the message to the home AS when the user is roaming subscriber. Then, the user sends ticket-granting ticket (TGT) to Ticket-Granting Server (TGS) to obtain for service-granting ticket. Finally, depending on service-granting ticket, user will access the network service he wants. The main purpose of the second and fourth proposed protocols is to enhance the security of authentication in WLAN. At first, a roaming user obtains the visit TGT form visit AS after a series of authentication steps. Then, the user exchanges service-granting ticket via visit TGT for AP and desirable server, and takes service-granting ticket of AP to authenticate AP. Finally, mutual authentication is achieved by way of the response which is encrypted with session key between the user and desirable server. The contributions of our research are as follows: (1) Four new protocols authentication applied to wireless local area network are given. (2) We combine traditional Kerberos protocol and public key cryptosystems to prevent effectively the replay attack and man-in-middle attack. (3) We can use our original registered information to access the network service worldwide by proposed Cross-Realm Authentication. It is believed that the results of our research in this thesis will be probably practical and efficient on the security of the wireless local area network. Shih-Hsiung Twu 涂世雄 2003 學位論文 ; thesis 75 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 中原大學 === 電機工程研究所 === 91 === Abstract
In this thesis, we propose four new authentication protocols for Single-Realm and Cross-Realm Authentications based on multiple Kerberi authentication technique. Single-Realm authentication is used when user is in the home area. Cross-Realm authentication with multiple Kerberi protocols achieves the goal that users roam anytime around worldwide. The roaming user can be authenticated in the visit area by his home authentication server (AS). Additionally, because of insecure feature of symmetric cryptosystems, we adopt public key cryptosystems to realize the proposed protocols.
In the first and third proposed protocols, the actions for user authenticates with access point (AP) is reduced to speed up the authentication time. At first, AS receives the identity from the user and forwards the message to the home AS when the user is roaming subscriber. Then, the user sends ticket-granting ticket (TGT) to Ticket-Granting Server (TGS) to obtain for service-granting ticket. Finally, depending on service-granting ticket, user will access the network service he wants.
The main purpose of the second and fourth proposed protocols is to enhance the security of authentication in WLAN. At first, a roaming user obtains the visit TGT form visit AS after a series of authentication steps. Then, the user exchanges service-granting ticket via visit TGT for AP and desirable server, and takes service-granting ticket of AP to authenticate AP. Finally, mutual authentication is achieved by way of the response which is encrypted with session key between the user and desirable server.
The contributions of our research are as follows: (1) Four new protocols authentication applied to wireless local area network are given. (2) We combine traditional Kerberos protocol and public key cryptosystems to prevent effectively the replay attack and man-in-middle attack. (3) We can use our original registered information to access the network service worldwide by proposed Cross-Realm Authentication.
It is believed that the results of our research in this thesis will be probably practical and efficient on the security of the wireless local area network.
|
author2 |
Shih-Hsiung Twu |
author_facet |
Shih-Hsiung Twu Yu-Hung Lai 賴昱宏 |
author |
Yu-Hung Lai 賴昱宏 |
spellingShingle |
Yu-Hung Lai 賴昱宏 Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) |
author_sort |
Yu-Hung Lai |
title |
Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) |
title_short |
Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) |
title_full |
Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) |
title_fullStr |
Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) |
title_full_unstemmed |
Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) |
title_sort |
cross-realm authentication based on multiple kerberi in wlan (ieee 802.1x) |
publishDate |
2003 |
url |
http://ndltd.ncl.edu.tw/handle/s369np |
work_keys_str_mv |
AT yuhunglai crossrealmauthenticationbasedonmultiplekerberiinwlanieee8021x AT làiyùhóng crossrealmauthenticationbasedonmultiplekerberiinwlanieee8021x AT yuhunglai yǐduōzhòngkerberosjiàngòuwúxiànqūyùwǎnglùzhīquányùrènzhèng AT làiyùhóng yǐduōzhòngkerberosjiàngòuwúxiànqūyùwǎnglùzhīquányùrènzhèng |
_version_ |
1718706035594625024 |