0% found this document useful (0 votes)
10 views31 pages

Chapter#4

Chapter 4 discusses key distribution and user authentication, emphasizing the importance of user authentication as a primary defense in computer security. It covers various means of authentication, symmetric and asymmetric key distribution methods, and details the Kerberos authentication system, including its versions and functionalities. Additionally, it addresses public-key infrastructure, X.509 certificates, and the management of identities in federated systems.

Uploaded by

nfqds4hqzp
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views31 pages

Chapter#4

Chapter 4 discusses key distribution and user authentication, emphasizing the importance of user authentication as a primary defense in computer security. It covers various means of authentication, symmetric and asymmetric key distribution methods, and details the Kerberos authentication system, including its versions and functionalities. Additionally, it addresses public-key infrastructure, X.509 certificates, and the management of identities in federated systems.

Uploaded by

nfqds4hqzp
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 4

Key Distribution and User


Authentication

T. Reem Assiri

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Remote user authentication principles

• In most computer security contexts, user authentication is


the fundamental building block and the primary line of
defense

• User authentication is the basis for most types of access


control and for user accountability

• RFC 4949 (Internet Security Glossary) defines user


authentication as the process of verifying an identity
claimed by or for a system entity
• Identification step
• Presenting an identifier to the security system
• Verification step
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
• Presenting or generating authentication information that
NIST Model for Electronic User
Authentication
• NIST SP 800-63-2 (Electronic Authentication Guideline,
August 2013 defines electronic user authentication as the
process of establishing confidence in user identities that
are presented electronically to an information system

• Systems can use the authenticated identity to determine if


the authenticated individual is authorized to perform
particular functions

• In many cases, the authentication and transaction or other


authorized function take place across an open network
such as the Internet

• Equally, authentication and subsequent authorization can


© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.

take place locally, such as across a local area network


© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
Means of authentication
• There are four general means of authenticating a user’s
identity, which can be used alone or in combination
• Something the individual knows
• Examples include a password, a personal identification number
(PIN), or answers to a prearranged set of questions
• Something the individual possesses
• Examples include cryptographic keys, electronic keycards, smart
cards, and physical keys
• This type of authenticator is referred to as a token
• Something the individual is (static biometrics)
• Examples include recognition by fingerprint, retina, and face
• Something the individual does (dynamic biometrics)
• Examples include recognition by voice pattern, handwriting
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
characteristics, and typing rhythm
Symmetric Key Distribution using
symmetric encryption
• For symmetric encryption to work, the two parties to an
exchange must share the same key, and that key must be
protected from access by others

• Frequent key changes are usually desirable to limit the


amount of data compromised if an attacker learns the key

• Key distribution technique


• The means of delivering a key to two parties that wish to
exchange data, without allowing others to see the key

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Key Distribution
• For two parties A and B, there are the following options:

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Kerberos
• Key distribution and user authentication service developed at
MIT

• Provides a centralized authentication server whose function is


to authenticate users to servers and servers to users

• Relies exclusively on symmetric encryption, making no use


of public-key encryption

Two versions are in use


•Version 4 implementations still exist, although this version is being phased out
•Version 5 corrects some of the security deficiencies of version 4 and has been issued as a proposed Internet Standard (RFC 4120)

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Kerberos version 4

• A basic third-party authentication scheme

• Authentication Server (AS)


• Users initially negotiate with AS to identify self
• AS provides a non-corruptible authentication credential
(ticket granting ticket TGT)

• Ticket Granting Server (TGS)


• Users subsequently request access to other services from
TGS on basis of users TGT

• Complex protocol using DES

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Table 4.1
Summary of Kerberos Version 4 Message Exchanges

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
© 2017 Pearson Education, Inc.,
Hoboken, NJ. All rights reserved.
© 2017 Pearson Education, Inc.,
Hoboken, NJ. All rights reserved.
Kerberos Realms
• Kerberos realm
• A set of managed nodes that share
the same Kerberos database
• The Kerberos database resides on
the Kerberos master computer
system, which should be kept in a
physically secure room
• A read-only copy of the Kerberos
database might also reside on other
Kerberos computer systems
• All changes to the database must be
made on the master computer
system
• Changing or accessing the contents
of a Kerberos database requires the
Kerberos
© 2017 Pearson master
Education, Inc., password
Hoboken, NJ. All rights reserved.
Kerberos principal

• A service or user that is known to the Kerberos system

• Each Kerberos principal is identified by its principal name

Principal names consist of three parts

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Differences between versions
4 and 5
Environmental
Technical deficiencies
shortcomings

• Encryption system • Double encryption


dependence
• PCBC encryption
• Internet protocol dependence
• Session keys
• Message byte ordering
• Password attacks
• Ticket lifetime

• Authentication forwarding

• Interrealm authentication

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
Key distribution using asymmetric
encryption
• One of the major roles of public-key encryption is to
address the problem of key distribution

• There are two distinct aspects to the use of public-key


encryption in this regard:
• The distribution of public keys
• The use of public-key encryption to distribute secret keys

• Public-key certificate
• Consists of a public key plus a user ID of the key owner,
with the whole block signed by a trusted third party
• Typically, the third party is a certificate authority (CA) that is
trusted by the user community, such as a government agency
or a financial institution
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
X.509 Certificates

• ITU-T recommendation X.509 is part of the X.500 series


of recommendations that define a directory service

• Defines a framework for the provision of authentication


services by the X.500 directory to its users

• The directory may serve as a repository of public-key


certificates

• Defines alternative authentication protocols based on the


use of public-key certificates
• Was initially issued in 1988
• Based on the use of public-key cryptography and digital
signatures
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
Obtaining a user’s certificate

• User certificates generated by a CA have the following


characteristics:
• Any user with access to the public key of the CA can verify
the user public key that was certified
• No party other than the certification authority can modify the
certificate without this being detected

• Because certificates are unforgeable, they can be placed in


a directory without the need for the directory to make
special efforts to protect them

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
Revocation of certificates
• Each certificate includes a period of validity

• Typically a new certificate is issued just before the expiration


of the old one

• It may be desirable on occasion to revoke a certificate before


it expires for one of the following reasons:
• The user’s private key is assumed to be compromised
• The user is no longer certified by this CA; reasons for this include
subject’s name has changed, the certificate is superseded, or the
certificate was not issued in conformance with the CA’s policies
• The CA’s certificate is assumed to be compromised

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


X.509 Version 3

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Key and policy information
• These extensions convey additional information about the
subject and issuer keys, plus indicators of certificate
policy

• A certificate policy is a named set of rules that indicates


the applicability of a certificate to a particular community
and/or class of application with common security
requirements

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Certificate subject and issuer
attributes
• These extensions support alternative names, in alternative
formats, for a certificate subject or certificate issuer and
can convey additional information about the certificate
subject to increase a certificate user’s confidence that the
certificate subject is a particular person or entity

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Certification path constraints

• These extensions allow constraint specifications to be


included in certificates issued for CAs by other CAs

• The constraints may restrict the types of certificates that


can be issued by the subject CA or that may occur
subsequently in a certification chain

© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.


Summary
• Remote user authentication
• X.509 certificates
principles
• Certificates
• The NIST model for electronic
user authentication • X.509 Version 3
• Means of authentication
• Public-key infrastructure
• Symmetric key distribution • PKIX management functions
using symmetric encryption • PKIX management protocols

• Kerberos • Federated identity


• Version 4 management
• Version 5 • Identity management
• Identity federation
• Key distribution using
asymmetric encryption
• Public-key certificates
© 2017 Pearson Education, Inc., Hoboken, NJ. All rights reserved.
• Public-key distribution of secret

You might also like