Security analysis of Kerberos protocol based on the strand space model

Wang Wei,Hu Mingzeng,Zhang zhaoxin
DOI: https://doi.org/10.3772/j.issn.1002-0470.2008.09.005
2008-01-01
Abstract:Based on the deep research on the strand space theory and the Kerberos protocol,this paper analyzes the security of the Kerberos protocol using the strand space model.The analysis procedure and results show that the Kerberos protocol can guarantee the authentication based on the strand space theory and the secrecy of the server strand's nonce,but can not guarantee the secrecy of the initiator strand's nonce.It proves that the Kerberos protocol can achieve the function of security authentication but may suffer password guessing attacks.Aiming at this problem,this study improved the Ker- beros protocol and the improved protocol can guarantee the secrecy of the initiator strand's nonce and strengthen the abili- ty to defense password guessing attacks.
What problem does this paper attempt to address?