Increasing Availability and Security of an Authentication Service

Increasing Availability and Security of an Authentication Service
复制标题

提高身份验证服务的可用性和安全性

DOI:
10.1109/49.223866
复制
发表时间:
1993
期刊:
IEEE J. Sel. Areas Commun.
影响因子:
--
通讯作者:
L. Gong
L. Gong
中科院分区:
--
文献类型:
--
作者:
L. Gong

文献摘要

被引文献

相似文献

身份验证通常是由身份验证服务器通过身份验证协议提供的,身份验证是指一个人对另一个人的身份声明表示满意的过程。身份验证服务的破坏可能导致整个系统的破坏,并且该服务是性能瓶颈,因为除非能够令人满意地建立相关方的身份,否则许多活动无法进行。因此,理想的身份验证服务应该既高度安全又高度可用。提出了一种通用的解决方案,即复制认证服务器,使少数恶意和串通的服务器不会危及安全性或中断服务。本文还讨论了这种分布式身份验证服务的一些不寻常的特性,包括可用性和安全性之间的权衡。当客户端在身份验证之前无法识别或同意受信任的服务器时,这种分布式服务也很有用。例如,在一些协作或联邦系统中,客户机不能完全信任同一组服务器。>
Authentication, the process by which one satisfies another about one's claim of identity, is typically provided by an authentication server via an authentication protocol. Compromise of the authentication service can lead to the compromise of the whole system, and the service is a performance bottleneck because many activities cannot proceed unless the identities of concerned parties can be satisfactorily established. Therefore, a desirable authentication service should be both highly secure and highly available. A general solution in which the authentication server is replicated so that a minority of malicious and colluding servers cannot compromise security or disrupt service is proposed. Some unusual features of such a distributed authentication service, including the tradeoff between availability and security, are discussed. Such a distributed service is also useful when clients cannot identify or agree upon trusted servers prior to authentication. For example, in some cooperative or federated systems, clients simply cannot all trust the same set of servers. >