Academia.eduAcademia.edu

On inter-realm authentication in large distributed systems

1991, Proceedings. 25th Annual 1991 IEEE International Carnahan Conference on Security Technology

Abstract

In this paper we define and rationalize a policy for propagation of authentication trust across realm boundaries. This policy helps limit global security exposures that ensue whenever an authentication service is compromised. It is based on a hierarchical model of inter-realm authentication, and can be supported by both public-key and secret-key systems. As an example, we present a simple protocol which selects inter-realm authentication paths that satis~the policy. The protocol is part of a design which provides application transparency for inter-realm, authentication-path selection and acceptance as the default mode of opera lion. The design can be integrated with the security services of existing systems; e.g., of the Open Software Foundation's Distributed Coinputing Environment (DCE). DCE implementation issues are also discussed.