An Improved Kerberos Protocol Based on Diffie-Hellman-DSA Key Exchange.

Zhao Hu,Yuesheng Zhu,Limin Ma
DOI: https://doi.org/10.1109/icon.2012.6506591
2012-01-01
Abstract:Kerberos is a widely-used network authentication protocol based on a trusted third-party. PKINIT, an enhanced Kerberos protocol which uses PKI mechanism, can prevent the password guessing attack, however, it introduces excessive amount of computational power. To enhance the security performance and computation efficiency of Kerberos, in this paper an improved Kerberos protocol based on Diffie-Hellman-DSA (DH-DSA) key exchange is proposed. Mutual authentication and key exchange between the client and Authentication Server (AS) can be simultaneously achieved with the proposed approach. Our experimental and analysis results have demonstrated that this new protocol can resist the password guessing attack and is more efficient and easily deployed than PKINIT.
What problem does this paper attempt to address?