Lee-Sub Lee, Kyung-Ryong Choi, Dongwon Jeong, Soo-Hyun Park, JuHum Kwon
{"title":"An Inter-Domain Authentication Mechanism for XMPP/Jabber","authors":"Lee-Sub Lee, Kyung-Ryong Choi, Dongwon Jeong, Soo-Hyun Park, JuHum Kwon","doi":"10.1109/SERA.2006.15","DOIUrl":null,"url":null,"abstract":"Although Jabber started from the instance messaging protocol, it became one of the most important toolkits for developing distributed applications. The existing Jabber authentication model doesn't support a mechanism to enable a client to access the servers in another domain directly. This limitation causes data duplication and synchronization problems in developing Jabber based distributed applications. Thus the study proposes a novel IDA (inter-domain authentication). While the well-known Kerberos authentication protocol provides IRA (inter-realm authentication), it requires all realms to implement Kerberos authentication mechanisms. Thus this cannot be used for developing Jabber services which contains various authentication mechanisms simultaneously. The study also presents the verification of security completeness with formal method, BAN logic","PeriodicalId":187207,"journal":{"name":"Fourth International Conference on Software Engineering Research, Management and Applications (SERA'06)","volume":"277 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-08-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Fourth International Conference on Software Engineering Research, Management and Applications (SERA'06)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SERA.2006.15","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Although Jabber started from the instance messaging protocol, it became one of the most important toolkits for developing distributed applications. The existing Jabber authentication model doesn't support a mechanism to enable a client to access the servers in another domain directly. This limitation causes data duplication and synchronization problems in developing Jabber based distributed applications. Thus the study proposes a novel IDA (inter-domain authentication). While the well-known Kerberos authentication protocol provides IRA (inter-realm authentication), it requires all realms to implement Kerberos authentication mechanisms. Thus this cannot be used for developing Jabber services which contains various authentication mechanisms simultaneously. The study also presents the verification of security completeness with formal method, BAN logic