User Org
KDC
User
Broker
Application
User Org
AAA Server
TGT
UOST
UOST (Binding),
Auth
AM
(Binding)
CERT
(Binding)
CERT
(Binding)
CERT (Binding)
OK
Figure 5a - Inter-Domain Push Sequence
User Org Performs Authentication and Authorization
Trusted Broker Signs Authorization
KDC: Kerberos Key Distribution Center
TGT: Ticket Granting Ticket
UOST: User Org AAA Server Service Ticket
Auth: Authenticator created by User and encrypted with UOST session key
AM: Message authorizing User to Application / Can be bound to: User name or ID, User IP address (these could be sent through AM) , secure channel session between User and Application (if created - would need to pass the session key or identifier to the AAA server)
CERT: Created from AM and signed by trusted Broker
Binding: User IP addr, or User name, or User/Application secure session ID, etc …
Secure Channel
Previous slide | Next slide | Back to first slide | View graphic version |