Abstract
dc:description.abstractOrganizations need to provide services to a wide range of people, including strangers outside their local security domain. As the number of users grows larger, it becomes increasingly tedious to maintain and provision user accounts. It remains an open problem to create a system for provisioning outsiders that is secure, flexible, efficient, scalable, and easy to manage. Kerberos is a secure, industry-standard protocol. Currently, Kerberos operates as a closed system; all users must be specified upfront and managed on an individual basis. This paper presents EPAK (Extensible Pre-Authentication in Kerberos), a framework that enables Kerberos to operate as an open system. Implemented as a Kerberos extension, EPAK enables many authentication schemes to be loosely coupled with Kerberos, without further modification to Kerberos. EPAK provides the mutual benefits of enhancing the flexibility of Kerberos and increasing the viability of alternate authentication systems as they move to the enterprise.
Degree
thesis:*- Name thesis:degree_name
- MS
- Grantor dc:publisher
- Brigham Young University - Provo
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Hellewell, Phillip L.
Subjects
dc:subject × 6Rights
- Language dc:language
- English
Identifiers
dc:identifier.*- Repository record dc:identifier
- https://scholarsarchive.byu.edu/etd/1395
- OAI identifier oai:identifier
- oai:scholarsarchive.byu.edu:etd-2394