Abstract
SESAMEV4 is a security architecture that supports role based access control with single sign-on facilities for heterogenous distributed network environments. Several vulnerabilities are identified in SESAMEV4’s user authentication process. This paper proposes four options for enhancing this user authentication process by integrating smart cards into SESAMEV4. The proposals are shown to successfully increase the level of security of SESAMEV4 and will be shown to correctly operate with existing SESAMEV4 applications and servers, with no modifications required to the applications or servers.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Ashley, P., Vandenwauver, M.: Practical Intranet Security: Overview of the State of the Art and Available Technologies. Kluwer Academic Publishers, Dordrecht (1998)
Bellovin, S., Meritt, M.: Limitations of the Kerberos Authentication System. Computer Communications Review 20(5), 119–132 (1990)
Gaskell, G., Looi, M.: Integrating Smart Cards into Authentication Systems. In: Dawson, E.P., Golić, J.D. (eds.) Cryptography: Policy and Algorithms 1995. LNCS, vol. 1029, pp. 270–281. Springer, Heidelberg (1996)
Kaijser, P.: SESAMEV4 The European Solution to Security for Open Systems. In: Proceedings of the 10th World Conference on Computer Security, Audit and Control COMPSEC, London, UK, pp. 289–297 (October 1993)
Kaijser, P., Parker, T., Pinkas, D.: SESAMEV4: The Solution to Security for Open Distributed Systems. Computer Communications 17(7), 501–518 (1994)
Kohl, J., Neumann, C.: The Kerberos Network Authentication Service V5, Internet RFC 1510 (1993)
Steiner, J., Neuman, C., Schiller, J.: Kerberos: An Authentication Service for Open Network Systems. In: Proceedings of the 1988 Usenix Winter Conference, Texas, USA, pp. 191–202 (February 1988)
Vandenwauver, M., Govaerts, R., Vandewalle, J.: Security of Client Server Systems. In: Proceedings of 2nd International Small Systems Security Conference, IFIP (1997)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2000 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Looi, M., Ashley, P., Seet, L.T., Au, R., Gaskell, G., Vandenwauver, M. (2000). Enhancing SESAMEV4 with Smart Cards. In: Quisquater, JJ., Schneier, B. (eds) Smart Card Research and Applications. CARDIS 1998. Lecture Notes in Computer Science, vol 1820. Springer, Berlin, Heidelberg. https://doi.org/10.1007/10721064_17
Download citation
DOI: https://doi.org/10.1007/10721064_17
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-67923-3
Online ISBN: 978-3-540-44534-0
eBook Packages: Springer Book Archive