在对串空间理论和Kerberos协议进行深入研究的基础上,采用串空间理论模型对Kerberos协议进行了安全性分析。分析的过程和结果证明,Kerberos协议满足串空间理论的认证性和服务器串随机数的秘密性,但不能保证发起者串随机数的秘密性,因此Kerberos协议能实现安全认证功能,但存在口令猜测攻击。针对此问题,对Kerberos协议进行改进,改进后的协议满足发起者串随机数秘密性,增强了抗口令猜测攻击的能力。
Based on the deep research on the strand space theory and the Kerberos protocol, this paper analyzes the security of the Kerberos protocol using the strand space model. The analysis procedure and results show that the Kerberos protocol can guarantee the authentication based on the strand space theory and the secrecy of the server strand's nonce, but can not guarantee the secrecy of the initiator strand's nonce. It proves that the Kerberos protocol can achieve the function of security authentication but may suffer password guessing attacks. Aiming at this problem, this study improved the Kerberos protocol and the improved protocol can guarantee the secrecy of the initiator strand' s nonce and strengthen the ability to defense password guessing attacks.