Key Distribution Center

E718987

A Key Distribution Center is a trusted server in authentication protocols like Kerberos that issues and manages cryptographic keys and tickets to securely verify users and services.

All labels observed (4)

Label Occurrences
Authentication Center 4
Key Distribution Center canonical 2
Ticket Granting Server 2

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf authentication infrastructure component ⓘ
cryptographic key management system ⓘ
network security component ⓘ
trusted third party ⓘ
communicatesWith application servers ⓘ
clients ⓘ
domain controllers in Active Directory ⓘ
definedIn Kerberos Version 5 specification ⓘ
linked to: Kerberos
goal enable secure single sign-on ⓘ
prevent password transmission over the network ⓘ
provide mutual authentication ⓘ
hasComponent Authentication Server ⓘ
Ticket Granting Server ⓘ
hasRole authenticates services ⓘ
authenticates users ⓘ
centralizes key management ⓘ
issues authentication tickets ⓘ
issues cryptographic keys ⓘ
mediates trust between clients and services ⓘ
implementedAs centralized server ⓘ
cluster of replicated servers ⓘ
manages secret keys shared with clients ⓘ
secret keys shared with services ⓘ
service tickets ⓘ
session keys ⓘ
ticket-granting tickets ⓘ
performsFunction encrypts ticket-granting tickets with KDC secret key ⓘ
encrypts tickets with service keys ⓘ
enforces authentication policy ⓘ
generates session keys for client–service communication ⓘ
limits ticket lifetimes ⓘ
supports single sign-on ⓘ
verifies client credentials ⓘ
relatedConcept Authentication Server ⓘ
Public Key Infrastructure ⓘ
Ticket Granting Server ⓘ
requires high availability ⓘ
secure storage of long-term keys ⓘ
secure time synchronization ⓘ
strong access control ⓘ
supportsEnvironment Windows Active Directory domains ⓘ
enterprise networks ⓘ
usedInProtocol Kerberos ⓘ
Needham–Schroeder-style authentication protocols ⓘ
usesCryptography symmetric key cryptography ⓘ
time-stamped authenticators ⓘ
vulnerableTo compromise of all issued keys if KDC master key is exposed ⓘ
single point of failure if not replicated ⓘ

How these facts were elicited

Referenced by (9)

Full triples — surface form annotated when it differs from this entity's canonical label.

Kerberos → hasComponent → Key Distribution Center ⓘ
Home Location Register → communicatesWith → Authentication Center ⓘ
linked to: Key Distribution Center
Home Subscriber Server → relatedTo → Authentication Center ⓘ
linked to: Key Distribution Center
HLR → communicatesWith → Authentication Center ⓘ
linked to: Key Distribution Center
VLR → interactsWith → Authentication Center ⓘ
linked to: Key Distribution Center
Key Distribution Center → hasComponent → Ticket Granting Server ⓘ
linked to: Key Distribution Center
Key Distribution Center → relatedConcept → Ticket Granting Server ⓘ
linked to: Key Distribution Center
RFC 4120 → definesComponent → Key Distribution Center ⓘ
RFC 4120 → definesComponent → Ticket-Granting Service ⓘ
linked to: Key Distribution Center