18.11.2014 Views

Anais - Engenharia de Redes de Comunicação - UnB

Anais - Engenharia de Redes de Comunicação - UnB

Anais - Engenharia de Redes de Comunicação - UnB

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IdP+<br />

5. Requests the<br />

certificate proof<br />

4. Authentication 7. Issues the<br />

attribute<br />

3. is redirected assertions<br />

2. Selects your<br />

IdP<br />

1. Attempts to access<br />

6. Sends the proof<br />

2. is redirected<br />

8. Sends the script to make the certificate<br />

request<br />

9. Creates/Sends the user<br />

certificate<br />

NA<br />

Certificate<br />

Generator<br />

Service<br />

(SP)<br />

Figure 5. Grid certificate generation.<br />

6. Conclusion and Future Works<br />

This new mo<strong>de</strong>l of Public Key Infrastructure, NBPKI, provi<strong>de</strong>s some facilities for digital<br />

signature validation. This mo<strong>de</strong>l uses self-signed certificates for the users, and the<br />

Certificate Authority is replaced by the Notarial Authority. The NA is responsible for the<br />

emission of tokens which are like a validation proof of the user certificate. With these<br />

tokens, it is not necessary to verify and validate the certificate chain of the user certificate,<br />

to check the certificate revocation lists nor the Time Stamping Authority is necessary.<br />

This new mo<strong>de</strong>l is useful for improving authentication process in services which<br />

use X.509 certificates within an aca<strong>de</strong>mic fe<strong>de</strong>rated environment. The Shibboleth Fe<strong>de</strong>rations<br />

can be more usable when have more support to use different authentication cre<strong>de</strong>ntials.<br />

The use of self-signed certificates improves the facilities of the certificates management,<br />

the use of certificates for authentication processes and even the security of the<br />

user authentication. The facilities of the issue of digital certificates without losing the<br />

infrastructure security and integrating with the aca<strong>de</strong>mic institutions through Shibboleth<br />

Fe<strong>de</strong>rations, becomes this mo<strong>de</strong>l one positive different view for the increase of the use of<br />

digital certificates for authentication.<br />

The authentication structure does not need to suffer a lot of alterations in the aca<strong>de</strong>mic<br />

fe<strong>de</strong>rated infrastructure and in the protocols used. The complexity nee<strong>de</strong>d by the<br />

standard certificate verification may be kept asi<strong>de</strong> whether self-signed certificate is used<br />

for the authentication process.<br />

The NBPKI and the IdP+ were implemented in Java language due to be portable<br />

and the facility in web applications <strong>de</strong>velopment. The next stages for the improvement<br />

of this work is to perform tests to verify the impacts due to the use of the authentication<br />

based on self-signed certificates in the Shibboleth Fe<strong>de</strong>rations.<br />

412

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!