Implementation of a security service provider for intranets

Joint Authors

Ali, Hamid M.
Fulayyih, Wamid Nizar

Source

Journal of Engineering

Issue

Vol. 14, Issue 2 (30 Jun. 2008), pp.2416-2428, 13 p.

Publisher

University of Baghdad College of Engineering

Publication Date

2008-06-30

Country of Publication

Iraq

No. of Pages

13

Main Subjects

Information Technology and Computer Science

Topics

Abstract AR

يعتبر التصديق و الخصوصية من أهم فروع الأمن التي يجب توفيرها.

يقوم هذا البحث بدراسة التصديق مركزا على أنظمة التصديق المعتمدة في مجموعة أنظمة التشغيل Windows 2000 و خصوصا Kerberos.

كنتيجة لهذه الدراسة وجدت بعض النقاط غير المقنعة و بعض مواطن الضعف، كالتعرض ل offline dictionary attacks و عدم توفير perfect forwardsecrecy.

لذلك تم اختيار بعض البروتوكولات (للتصديق و الاتفاق على المفتاح) لبناء نظام تصديق يأخذ بنظر الاعتبار الملاحظات المأخوذة على الأنظمة في Windows 2000و بالاعتماد على هذا النظام قد طور مزود خدمة أمن.

هذا المزود المقترح يعزل المطور عن تعقيدات النظام التحتي.

Abstract EN

mong the many branches of security, authentication and confidentiality are very important to be provided.

This work studies authentication focusing on the authentication systems supported by Windows 2000 family, especially Kerberos.

As a result of this study, some unconvincing points are found along with others that are considered as weaknesses, such as being subject to offline dictionary attacks and the lack of perfect forward secrecy.

Hence, some protocols (for authentication and key agreement) are chosen to build an authentication system that takes into consideration the observations on Windows 2000 systems.

Based on this system, a security service provider is developed.

The proposed provider isolates the developer from the complexity of the underlying system.

American Psychological Association (APA)

Ali, Hamid M.& Fulayyih, Wamid Nizar. 2008. Implementation of a security service provider for intranets. Journal of Engineering،Vol. 14, no. 2, pp.2416-2428.
https://search.emarefa.net/detail/BIM-332262

Modern Language Association (MLA)

Ali, Hamid M.& Fulayyih, Wamid Nizar. Implementation of a security service provider for intranets. Journal of Engineering Vol. 14, no. 2 (Jun. 2008), pp.2416-2428.
https://search.emarefa.net/detail/BIM-332262

American Medical Association (AMA)

Ali, Hamid M.& Fulayyih, Wamid Nizar. Implementation of a security service provider for intranets. Journal of Engineering. 2008. Vol. 14, no. 2, pp.2416-2428.
https://search.emarefa.net/detail/BIM-332262

Data Type

Journal Articles

Language

English

Notes

Includes appendix : p. 2427-2428

Record ID

BIM-332262