The Experts below are selected from a list of 30 Experts worldwide ranked by ideXlab platform
Yosi Mass - One of the best experts on this subject based on the ideXlab platform.
-
Relying Party Credentials Framework
Electronic Commerce Research, 2004Co-Authors: Amir Herzberg, Yosi MassAbstract:We present architecture for a relying-party to manage Credentials, and in particular to map different Credentials into common format and semantics. This will allow use of simple, widely available Credentials as well as more advanced Credentials such as public key certificates, attribute certificates and 'negative' Credentials (which result in reduced trust) such as certificate revocation lists (CRL). The core of the architecture is a Credential Manager who collects Credentials, and maps them to common format and semantics.
-
CT-RSA - Relying Party Credentials Framework
Topics in Cryptology — CT-RSA 2001, 2001Co-Authors: Amir Herzberg, Yosi MassAbstract:We present architecture for e-business applications that receive requests from a party over the Net, to allow the applications to make decisions relying on the Credentials of the requesting party. Relying party applications will be provided with uniform interface to the Credentials of the requesting party. This will allow use of simple, widely available Credentials as well as more advanced Credentials such as public key certificates, attribute certificates and 'Negative' Credentials such as certificate revocation lists (CRL). The core of the architecture is a Credential Manager who will provide all Credential management functions, including collection of Credentials, providing uniform interface to Credentials, and extracting semantics relevant to the relying party's applications.
David Benjamin - One of the best experts on this subject based on the ideXlab platform.
-
Adapting Kerberos for a Browser-based Environment
2013Co-Authors: David Benjamin, Nickolai ZeldovichAbstract:This thesis presents Webathena, a browser-centric implementation of the Kerberos network authentication protocol. It consists of a JavaScript Kerberos client, paired with a simple, untrusted, server-side proxy to wrap the protocol in HTTP. This is used to implement a trusted Credential Manager with a cross-origin protocol to delegate Credentials to untrusted Web applications. To evaluate Webathena, we present Roost, a Web-based client for the Zephyr messaging and notification in use at MIT, along with a host of proof-of-concept applications. We find that it is possible to build Web-based clients for Kerberized services similar to or better than existing native ones with no modifications to either the Kerberos KDCs or the services themselves. Finally, we discuss possible modifications to Kerberos to better support this kind of Credential delegation
-
Adapting Kerberos for a browser-based environment
2013Co-Authors: David BenjaminAbstract:This thesis presents Webathena, a browser-centric implementation of the Kerberos network authentication protocol. It consists of a JavaScript Kerberos client, paired with a simple, untrusted, server-side proxy to wrap the protocol in HTTP. This is used to implement a trusted Credential Manager with a cross-origin protocol to delegate Credentials to untrusted Web applications. To evaluate Webathena, we present Roost, a Web-based client for the Zephyr messaging and notification in use at MIT, along with a host of proof-of-concept applications. We find that it is possible to build Web-based clients for Kerberized services similar to or better than existing native ones with no modifications to either the Kerberos KDCs or the services themselves. Finally, we discuss possible modifications to Kerberos to better support this kind of Credential delegation. Thesis Supervisor: Nickolai Zeldovich Title: Associate Professor
Amir Herzberg - One of the best experts on this subject based on the ideXlab platform.
-
Relying Party Credentials Framework
Electronic Commerce Research, 2004Co-Authors: Amir Herzberg, Yosi MassAbstract:We present architecture for a relying-party to manage Credentials, and in particular to map different Credentials into common format and semantics. This will allow use of simple, widely available Credentials as well as more advanced Credentials such as public key certificates, attribute certificates and 'negative' Credentials (which result in reduced trust) such as certificate revocation lists (CRL). The core of the architecture is a Credential Manager who collects Credentials, and maps them to common format and semantics.
-
CT-RSA - Relying Party Credentials Framework
Topics in Cryptology — CT-RSA 2001, 2001Co-Authors: Amir Herzberg, Yosi MassAbstract:We present architecture for e-business applications that receive requests from a party over the Net, to allow the applications to make decisions relying on the Credentials of the requesting party. Relying party applications will be provided with uniform interface to the Credentials of the requesting party. This will allow use of simple, widely available Credentials as well as more advanced Credentials such as public key certificates, attribute certificates and 'Negative' Credentials such as certificate revocation lists (CRL). The core of the architecture is a Credential Manager who will provide all Credential management functions, including collection of Credentials, providing uniform interface to Credentials, and extracting semantics relevant to the relying party's applications.
Nickolai Zeldovich - One of the best experts on this subject based on the ideXlab platform.
-
Adapting Kerberos for a Browser-based Environment
2013Co-Authors: David Benjamin, Nickolai ZeldovichAbstract:This thesis presents Webathena, a browser-centric implementation of the Kerberos network authentication protocol. It consists of a JavaScript Kerberos client, paired with a simple, untrusted, server-side proxy to wrap the protocol in HTTP. This is used to implement a trusted Credential Manager with a cross-origin protocol to delegate Credentials to untrusted Web applications. To evaluate Webathena, we present Roost, a Web-based client for the Zephyr messaging and notification in use at MIT, along with a host of proof-of-concept applications. We find that it is possible to build Web-based clients for Kerberized services similar to or better than existing native ones with no modifications to either the Kerberos KDCs or the services themselves. Finally, we discuss possible modifications to Kerberos to better support this kind of Credential delegation
Benjamin, David A.) - One of the best experts on this subject based on the ideXlab platform.
-
Adapting Kerberos for a browser-based environment
Massachusetts Institute of Technology, 2013Co-Authors: Benjamin, David A.)Abstract:Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2013.Cataloged from PDF version of thesis.Includes bibliographical references (pages 63-65).This thesis presents Webathena, a browser-centric implementation of the Kerberos network authentication protocol. It consists of a JavaScript Kerberos client, paired with a simple, untrusted, server-side proxy to wrap the protocol in HTTP. This is used to implement a trusted Credential Manager with a cross-origin protocol to delegate Credentials to untrusted Web applications. To evaluate Webathena, we present Roost, a Web-based client for the Zephyr messaging and notification in use at MIT, along with a host of proof-of-concept applications. We find that it is possible to build Web-based clients for Kerberized services similar to or better than existing native ones with no modifications to either the Kerberos KDCs or the services themselves. Finally, we discuss possible modifications to Kerberos to better support this kind of Credential delegation.by David Benjamin.M. Eng