首页> 外文会议>IEEE International Conference on Information Science and Technology >Time-based OTP authentication via secure tunnel (TOAST): A mobile TOTP scheme using TLS seed exchange and encrypted offline keystore
【24h】

Time-based OTP authentication via secure tunnel (TOAST): A mobile TOTP scheme using TLS seed exchange and encrypted offline keystore

机译:通过安全隧道(TOAST)的基于时间的OTP身份验证:一种使用TLS种子交换和加密的脱机密钥库的移动TOTP方案

获取原文

摘要

The main objective of this research is to build upon existing cryptographic standards and web protocols to design an alternative multi-factor authentication cryptosystem for the web. It involves seed exchange to a software-based token through a login-protected Transport Layer Security (TLS/SSL) tunnel, encrypted local storage through a password-protected keystore (BC UBER) with a strong key derivation function (PBEWithSHAANDTwofish-CBC), and offline generation of one-time passwords through the TOTP algorithm (IETF RFC 6239). Authentication occurs through the use of a shared secret (the seed) to verify the correctness of the one-time password used to authenticate. With the traditional use of username and password no longer wholly adequate for protecting online accounts, and with regulators worldwide toughening up security requirements (i.e. BSP 808, FFIEC), this research hopes to increase research effort on further development of cryptosystems involving multi-factor authentication.
机译:这项研究的主要目的是在现有的加密标准和Web协议的基础上,为Web设计替代的多因素身份验证密码系统。它涉及通过登录保护的传输层安全性(TLS / SSL)隧道将种子交换为基于软件的令牌,通过具有强密钥派生功能(PBEWithSHAANDTwofish-CBC)的受密码保护的密钥库(BC UBER)加密本地存储,以及通过TOTP算法(IETF RFC 6239)脱机生成一次性密码。身份验证是通过使用共享机密(种子)来验证用于身份验证的一次性密码的正确性。随着用户名和密码的传统使用不再完全足以保护在线帐户,并且全球监管机构都加强了对安全性的要求(例如BSP 808,FFIEC),这项研究希望加大对涉及多因素身份验证的密码系统进一步开发的研究力度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号