Abstract:This paper discusses Kerberos protocol and its security in detail, proposes an improved authentication model according to its limitations as well. This model aims at solving the problems such as password guess attack , replay attack and key storage management by using lightweight ticket and hybrid cryptosystem and USBKey two-factor authentication, which is safe and easy to realize.