首页> 外文期刊>Applied Sciences >Analysis of Vulnerabilities That Can Occur When Generating One-Time Password
【24h】

Analysis of Vulnerabilities That Can Occur When Generating One-Time Password

机译:生成一次性密码时可能发生的漏洞分析

获取原文

摘要

A one-time password (OTP) is a password that is valid for only one login session or transaction, in IT systems or digital devices. This is one of the human-centered security services and is commonly used for multi-factor authentication. This is very similar to generating pseudo-random bit streams in cryptography. However, it is only part of what is used as OTP in the bit stream. Therefore, the OTP mechanism requires an algorithm to extract portions. It is also necessary to convert hexadecimal to decimal so that the values of the bit strings are familiar to human. In this paper, we classify three algorithms for extracting the final data from the pseudo random bit sequence. We also analyze the fact that a vulnerability occurs during the extraction process, resulting in a high frequency of certain numbers; even if cryptographically secure generation algorithms are used.
机译:一次性密码(OTP)是IT系统或数字设备中仅对一个登录会话或事务有效的密码。这是以人为本的安全服务之一,通常用于多因素身份验证。这与在加密中生成伪随机比特流非常相似。但是,它只是在比特流中用作OTP的一部分。因此,OTP机制需要算法提取部分。还必须将十六进制转换为小数,以便人类的钻头字符串的值是熟悉的。在本文中,我们将三种算法分类用于从伪随机位序列中提取最终数据。我们还分析了在提取过程中发生漏洞的事实,导致某些数字的高频;即使使用加密安全的生成算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号