RFC1507 - DASS - Distributed Authentication Security Service(6)

时间:2005-02-14 来源: 作者: 点击:
digital signature A value computed from a block of data and a key which could only be computed by someone knowing the key. A digital signature computed with a secret key can only be verified by someo
  

digital signature
A value computed from a block of data
and a key which could only be computed by someone knowing
the key. A digital signature computed with a secret key can
only be verified by someone knowing that secret key. A
digital signature computed with a private key can be
verified by anyone knowing the corresponding public key.

encipher
To render incomprehensible except to the holder of a
particular key. If you encipher with a secret key, only the
holder of the same secret can decipher the message. If you
encipher with a public key, only the holder of the
corresponding private key can decipher it.

initial trust certificate
A certificate signed by a principal for its own use which
states the name and public key of a trusted authority.

global user name
A hierarchical name for a user which is
unique within the entire domain of discussion (typically the
network).

local user name
A simple (non-hierarchical) name by
which a user is known within a limited context such as on a
single computer.

principal
Abstract entity which can be authenticated by name.
In DASS there are user principals and server principals.

private key
Cryptographic key used in asymmetric (public key)
cryptography to decrypt and/or sign messages. In asymmetric
cryptography, knowing the encryption key is independent of
knowing the decryption key. The decryption (or signing)
private key cannot be derived from the encrypting (or
verifying) public key.

proxy
A mapping from an external name to a local account
name for purposes of establishing a set of local access
rights. Note that this differs from the definition in ECMA
TR/46.

public key
Cryptographic key used in asymmetric cryptography to
encrypt messages and/or verify signatures.

RSA
The Rivest-Shamir-Adelman public key cryptosystem
based on modular exponentiation where the modulus is the
product of two large primes. When the term RSA key is used,
it should be clear from context whether the public key, the
private key, or the public/private pair is intended.

secret key
Cryptographic key used in symmetric cryptography to
encrypt, sign, decrypt and verify messages. In symmetric
cryptography, knowledge of the decryption key implies
knowledge of the encryption key, and vice-versa.

sign
A process which takes a piece of data and a key and
produces a digital signature which can only be calculated by
someone with the key. The holder of a corresponding key can
verify the signature.

source
The initiator of an authentication exchange.

strong authentication
Authentication by means of cryptographically derived
authentication tokens and credentials. The actual working
definition is closer to that of "zero knowledge" proof:

authentication so as to not reveal any information usable by
either the verifier, or by an eavesdropping third party, to
further their potential ability to impersonate the claimant.

target
The intended second party (other than the source) to
an authentication exchange.

ticket
A data structure certifying an authenticating
(public) key by virtue of being signed by a user principal
using their (long term) private key. The ticket also
includes the UID of the principal.

trusted authority
The public key, name and UID of a
certification authority trusted in some context to certify
the public keys of other principals.

UID
A 128 bit unique identifier produced according to OSF
standard specifications.

user key
A "long term" RSA key whose private portion
authenticates its holder as having the access rights of a
particular person.

verify
To cryptographically process a piece of data and a
digital signature to determine that the holder of a
particular key signed the data.

verifier
The party who will perform the operations necessary
to verify the claimed identity of a claimant.

Security Considerations

Security issues are discussed throughout this memo.

Author's Address

Charles Kaufman
Digital Equipment Corporation
ZKO3-3/U14
110 Spit Brook Road
Nashua, NH 03062

Phone: (603) 881-1495
Email: kaufman@zk3.dec.com

General comments on this document should be sent to cat-ietf@mit.edu.
Minor corrections should be sent to the author.

------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容