Kerberos and SPNEGO

本文介绍了Kerberos认证协议及其在网络安全性中的作用,并详细阐述了SPNEGO如何将Kerberos单点登录环境扩展到Web应用程序中。通过标准HTTP协议,客户端应用程序能够从Web应用程序中获取服务。

Kerberos and SPNEGO

Kerberos is a network authentication protocol for client/server applications, and SPNEGO provides a mechanism for extending Kerberos to Web applications through the standard HTTP protocol.

Kerberos

Kerberos is an a authentication protocol, which allows nodes communicating over a non-secure network to prove their identity to one another in a secure manner. It is designed to provide strong authentication for client/server applications by using secret-key cryptography.

Kerberos was developed by the Massachusetts Institute of Technology (MIT) as a solution to its network security problems. It was named after the Greek mythological character Kerberos (or Cerberus). Several versions of the protocol exist, and the latest one is version 5 - RFC 4120 released in 2005.

The idea is very simple. If you want a service, you need to have a ticket for that service. To obtain a ticket, you must contact the Ticket Granting Service (TGS) to obtain a service ticket. Once the ticket is obtained, you can use it to gain access to the intent service offered by a Service Server (SS).

Extracted from the TechNet of Microsoft site - Kerberos Explained.

Kerberos is normally deployed in a client/server environment. It is rarely used in web-applications and thin client environments.

SPNEGO

Because of this, SPNEGO comes to the rescue. It stands for Simple and Protected GSS-API Negotiation Mechanism, which provides a mechanism for extending a Kerberos based single sign-on environment to web-applications.

The following diagrams shows how a client application obtains a service from a web-application through the standard HTTP protocol. Basically,

  • When an application (e.g. a browser) on the PC attempts to access a protected page on the web server, the server responds with an unauthorized response.
  • The application then requests a service ticket from the KDC, e.g. an Active Directory.
  • Once the required ticket is obtained, the application wraps it in a SPNEGO envelope and sends it over to the web server to request the same page again.
  • The server can then unpacks the envelope to retrieve the server ticket, and use it to authenticate the user.


Extracted from Jens Bo Friis presentation of SPNEGO authentication using JGSS

Resources

If you are interested in how Kerberos works, the following document illustrates the operation in a couple of simple diagrams.

A number of standards are available today that are related to the Kerberos authentication. They are:

  • RFC 4120 - The Kerberos Network Authentication Service (V5)
  • RFC 2743 - The Generic Security Services Application Program Interface (GSS-API)
  • RFC 4178 - The Simple and Protected GSS-API Negotiation Mechanism (SPNEGO)
  • RFC 4559 - SPNEGO-based Kerberos and NTLM HTTP Authentication in Microsoft Windows

Note: Microsoft supports the RFC 4559, which is a Microsoft version of SPNEGO with the ability to fall back to NTLM

内容概要:本文围绕间歇性光伏出力条件下48V直流母线电压的稳定控制与储能系统双向充放电的闭环调控体系展开深入研究,系统探讨了光伏阵列非线性输出特性与锂离子电池储能系统在离网直流微网中的能量均衡建模方法及分层控制策略。通过Simulink平台构建完整的光伏储能直流系统仿真模型,涵盖PV阵列、Boost DC-DC变换器、负载、双向DC-DC变换器及电池系统等关键组件,实现了最大功率点跟踪(MPPT)与储能系统的协同控制,有效应对光照波动引起的功率供需失衡问题。研究采用双PI闭环控制、模型预测控制(MPC)等多种先进控制算法,显著提升了系统的动态响应速度与直流母线电压稳定性,并实现了储能系统在削峰填谷中的优化运行,对于增强离网微网的供电可靠性与能源利用效率具有重要理论价值和工程意义。; 适合人群:具备电力电子、新能源系统或自动控制等相关领域基础知识的研究生、科研人员,以及从事微电网、光伏储能系统开发与设计的工程技术人员。; 使用场景及目标:① 构建适用于离网场景的光伏储能系统Simulink仿真模型;② 实现间歇性光照条件下48V直流母线电压的精确稳定控制与储能系统的双向能量管理;③ 研究MPPT控制与储能充放电策略之间的协同机制,提升系统在复杂工况下的运行稳定性与鲁棒性;④ 为微电网能量管理系统的设计、优化与性能验证提供可靠的理论依据和技术支撑。; 阅读建议:建议结合文中所述的Simulink仿真模型与控制算法,亲自动手实践建模与仿真全过程,重点关注MPPT控制策略的实现、双向DC-DC变换器的设计以及电压外环与电流内环构成的双闭环控制结构的参数整定,并通过设置不同的光照强度变化曲线和负载投切工况,全面测试和评估系统的动态响应能力与控制性能。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值