A practical one-time password authentication implement on Internet
Bin Li, Shaohai Hu, Y.-C.J. Liu
Abstract
Bin Li, Shaohai Hu, Y.-C.J. Liu
Abstract
A one-time password authentication protocol is proposed which can be used by common Internet users and services providers. The protocol is simple to implement and secure for common applications without additional hardware involved. Static password is used widely in conventional authentication. In the light of a threat of guessing attacks, a strong secret should be shared by communication participants. But the strong password is too hard to remember and easily eavesdropped by adversaries when transferred on-line. One-time password technology can counter replay attack resulted from eavesdropping. But existing one-time password schemes is too complicated to be accepted by common Internet users. The proposed protocol is simple to implement and secure for common Internet appliance without additional hardware involved. It is an improved version of challenge/response one-time password mechanism. (4 pages)
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
A one-time password authentication protocol is proposed which can be used by common Internet users and services providers. The protocol is simple to implement and secure for common applications without additional hardware involved. Static password is used widely in conventional authentication. In the light of a threat of guessing attacks, a strong secret should be shared by communication participants. But the strong password is too hard to remember and easily eavesdropped by adversaries when transferred on-line. One-time password technology can counter replay attack resulted from eavesdropping. But existing one-time password schemes is too complicated to be accepted by common Internet users. The proposed protocol is simple to implement and secure for common Internet appliance without additional hardware involved. It is an improved version of challenge/response one-time password mechanism. (4 pages)
Key concepts: Password, Computer science, One-time password, S/KEY, Computer security, Challenge–response authentication, Password strength, Eavesdropping