This document provides background information regarding large-scale Kerberos deployments in the industrial sector, with the aim of identifying issues in the current Kerberos cross-realm authentication model as defined in RFC 4120.
The wide popularity of Kerberos made it the de-facto standard for authentication in enterprise networks Moreover, the lightweight nature of Kerberos makes it a candidate of choice for securing network communications in emerging non-enterprise information systems such as industrial control networks, building automation and intelligent transportation systems. Many of these potential applications of Kerberos involve infrastructures characterized by their large scale and strict dependability requirements. However, such requirements may not be met when crossrealm Kerberos operations are involved. In this paper, we outline the issues with the current Kerberos crossrealm model and present XKDCP (Inter Key Distribution Center Protocol), a new Kerberos cross-realm authentication model that improves on scalability and dependability by (1) relying on public key cryptography to dynamically maintain direct trust relationships between Kerberos realms and (2) adopting a proxy model to offload inter-domain exchanges and processing from the low-end devices to the Kerberos authentication servers
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.