citeseer |
(0) (0 Votes)
|
Views: (1002) Date: (08-04-09) Pages: () |
Abstract: Available security solutions often are not widely used because the associated secure applications are awkward to use or they lack functionality when com? pared to standard insecure tools. To avoid this dicothomy ? we developed a non?intrusive ?or external ? client? server authentication framework which requires no modi?cation to both the clients and the servers. In this way ? full featured clients can be used to the satisfaction of the user community ? and o??the?shelf servers can be used with augmented security to the happiness of the system administrators. Our approach relies on software agents which use private keys and a challenge? response protocol to authenticate TCP?IP connection setup. The paper dis? cusses the general framework as well as a sample implementation. Attacks and countermeasures are also outlined. The approach explicitly doesn?t ad? dress data privacy during transmission ? as we would rather see it placed at application level.