Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)

碩士 === 中原大學 === 電機工程研究所 === 91 === Abstract In this thesis, we propose four new authentication protocols for Single-Realm and Cross-Realm Authentications based on multiple Kerberi authentication technique. Single-Realm authentication is used when user is in the home area. Cross-Realm authentication...

Full description

Bibliographic Details
Main Authors: Yu-Hung Lai, 賴昱宏
Other Authors: Shih-Hsiung Twu
Format: Others
Language:en_US
Published: 2003
Online Access:http://ndltd.ncl.edu.tw/handle/s369np
id ndltd-TW-091CYCU5442012
record_format oai_dc
spelling ndltd-TW-091CYCU54420122018-06-25T06:06:26Z http://ndltd.ncl.edu.tw/handle/s369np Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X) 以多重Kerberos建構無線區域網路之全域認證 Yu-Hung Lai 賴昱宏 碩士 中原大學 電機工程研究所 91 Abstract In this thesis, we propose four new authentication protocols for Single-Realm and Cross-Realm Authentications based on multiple Kerberi authentication technique. Single-Realm authentication is used when user is in the home area. Cross-Realm authentication with multiple Kerberi protocols achieves the goal that users roam anytime around worldwide. The roaming user can be authenticated in the visit area by his home authentication server (AS). Additionally, because of insecure feature of symmetric cryptosystems, we adopt public key cryptosystems to realize the proposed protocols. In the first and third proposed protocols, the actions for user authenticates with access point (AP) is reduced to speed up the authentication time. At first, AS receives the identity from the user and forwards the message to the home AS when the user is roaming subscriber. Then, the user sends ticket-granting ticket (TGT) to Ticket-Granting Server (TGS) to obtain for service-granting ticket. Finally, depending on service-granting ticket, user will access the network service he wants. The main purpose of the second and fourth proposed protocols is to enhance the security of authentication in WLAN. At first, a roaming user obtains the visit TGT form visit AS after a series of authentication steps. Then, the user exchanges service-granting ticket via visit TGT for AP and desirable server, and takes service-granting ticket of AP to authenticate AP. Finally, mutual authentication is achieved by way of the response which is encrypted with session key between the user and desirable server. The contributions of our research are as follows: (1) Four new protocols authentication applied to wireless local area network are given. (2) We combine traditional Kerberos protocol and public key cryptosystems to prevent effectively the replay attack and man-in-middle attack. (3) We can use our original registered information to access the network service worldwide by proposed Cross-Realm Authentication. It is believed that the results of our research in this thesis will be probably practical and efficient on the security of the wireless local area network. Shih-Hsiung Twu 涂世雄 2003 學位論文 ; thesis 75 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 中原大學 === 電機工程研究所 === 91 === Abstract In this thesis, we propose four new authentication protocols for Single-Realm and Cross-Realm Authentications based on multiple Kerberi authentication technique. Single-Realm authentication is used when user is in the home area. Cross-Realm authentication with multiple Kerberi protocols achieves the goal that users roam anytime around worldwide. The roaming user can be authenticated in the visit area by his home authentication server (AS). Additionally, because of insecure feature of symmetric cryptosystems, we adopt public key cryptosystems to realize the proposed protocols. In the first and third proposed protocols, the actions for user authenticates with access point (AP) is reduced to speed up the authentication time. At first, AS receives the identity from the user and forwards the message to the home AS when the user is roaming subscriber. Then, the user sends ticket-granting ticket (TGT) to Ticket-Granting Server (TGS) to obtain for service-granting ticket. Finally, depending on service-granting ticket, user will access the network service he wants. The main purpose of the second and fourth proposed protocols is to enhance the security of authentication in WLAN. At first, a roaming user obtains the visit TGT form visit AS after a series of authentication steps. Then, the user exchanges service-granting ticket via visit TGT for AP and desirable server, and takes service-granting ticket of AP to authenticate AP. Finally, mutual authentication is achieved by way of the response which is encrypted with session key between the user and desirable server. The contributions of our research are as follows: (1) Four new protocols authentication applied to wireless local area network are given. (2) We combine traditional Kerberos protocol and public key cryptosystems to prevent effectively the replay attack and man-in-middle attack. (3) We can use our original registered information to access the network service worldwide by proposed Cross-Realm Authentication. It is believed that the results of our research in this thesis will be probably practical and efficient on the security of the wireless local area network.
author2 Shih-Hsiung Twu
author_facet Shih-Hsiung Twu
Yu-Hung Lai
賴昱宏
author Yu-Hung Lai
賴昱宏
spellingShingle Yu-Hung Lai
賴昱宏
Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
author_sort Yu-Hung Lai
title Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
title_short Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
title_full Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
title_fullStr Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
title_full_unstemmed Cross-Realm Authentication Based on Multiple Kerberi in WLAN (IEEE 802.1X)
title_sort cross-realm authentication based on multiple kerberi in wlan (ieee 802.1x)
publishDate 2003
url http://ndltd.ncl.edu.tw/handle/s369np
work_keys_str_mv AT yuhunglai crossrealmauthenticationbasedonmultiplekerberiinwlanieee8021x
AT làiyùhóng crossrealmauthenticationbasedonmultiplekerberiinwlanieee8021x
AT yuhunglai yǐduōzhòngkerberosjiàngòuwúxiànqūyùwǎnglùzhīquányùrènzhèng
AT làiyùhóng yǐduōzhòngkerberosjiàngòuwúxiànqūyùwǎnglùzhīquányùrènzhèng
_version_ 1718706035594625024