Netinfo Security ›› 2019, Vol. 19 ›› Issue (10): 57-64.doi: 10.3969/j.issn.1671-1122.2019.10.008

Previous Articles     Next Articles

An Enhanced Kerberos Protocol Based on OTP with Formal Analysis

Limin MA(), Wei ZHANG, Ying SONG   

  1. Computer School, Beijing Information Science &Technology University, Beijing 100101, China
  • Received:2019-06-10 Online:2019-10-10 Published:2020-05-11
  • Contact: Limin MA E-mail:markgoogle@qq.com

Abstract:

Kerberos protocol is an important trusted third-party authentication protocol in distributed networks. It is widely used in mainstream operating systems, cloud computing, wireless networks and other application scenarios, but it is vulnerable to password guessing attacks, replay attacks and so on. Although PKINIT protocol based on public key cryptography can enhance the resistance of Kerberos protocol to these attacks, it needs to introduce too much computing resources and communication costs. Therefore, this paper proposes and implements a scheme based on one-time password mechanism to enhance the security of Kerberos protocol, and makes formal analysis based on BAN logic. The experimental results show that compared with the PKINIT protocol, the scheme reduces the computational complexity, reduces the initial authentication service time to 67.7% of the PKINIT protocol, and has the advantage of easy deployment.

Key words: Kerberos, PKINIT, OTP, password guessing attack, BAN logic

CLC Number: