1. To prevent attacks, the authenticator must be encrypted in Step (3). However,
ID: 3531746 • Letter: 1
Question
1. To prevent attacks, the authenticator must be encrypted in Step (3). However, the client does NOT know the long term key of the TGS. How can Kerberos let the TGS know the authenticator encryption key? Please give a complete answer.
2. After a while, the client will receive the ticket. Then the client will send the ticket to the server. However, this ticket itself is NOT sufficient for the server to offer the service to the client because Mallory may launch a serious attack. What can this work do to fool the server?
3. Because of the problem mentioned in Question 1.8, the client also needs to send another authenticator to the server. The authenticator will be encrypted by which key?
4. When the Server receives the authenticator and the ticket from the client. The server will compare the information items contained in the authenticator and the ticket to authenticate the client user
Explanation / Answer
Please find the solution as per your requirements.
If you have any doubt, please get back to me.
Any explanations needed, please get back to me. Thank You!
(1)
Answer:
It comes under the section of the analysis, “Authentication of KAS to client”.
Can Kerberos let the TGS know the authenticator encryption key?
Therefore, Kerberos allows the TGS to know the authenticator encryption key.
(2)
Answer:
The client will receive the ticket.
Here, the client-server exchange will take place.
Therefore, the intruder (Mallory) cannot know the Session Key (SK), it fools the person who launches the serious attack.
(3)
Answer:
With the reference to the answer (2),
Therefore, the authenticator will be encrypted by using the Session Key.
(4)
Answer:
When the Server receives the authenticator and the ticket from the client,
Therefore, the authentication will be done.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.