Research and Implementation of One-Time Password Authentication
碩士 === 樹德科技大學 === 資訊工程學系 === 94 === In the internet environment, user authentication is very important. Server can avoid illegal user with user authentication. A password-based scheme is the most generally used method of authentication on the internet. However, static password is used in conventiona...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2005
|
Online Access: | http://ndltd.ncl.edu.tw/handle/66641148672866986409 |
id |
ndltd-TW-094STU00392010 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-094STU003920102016-06-01T04:14:43Z http://ndltd.ncl.edu.tw/handle/66641148672866986409 Research and Implementation of One-Time Password Authentication 一次性通行碼認證之研究與實作 Chiang-Jiun Shie 謝鉛俊 碩士 樹德科技大學 資訊工程學系 94 In the internet environment, user authentication is very important. Server can avoid illegal user with user authentication. A password-based scheme is the most generally used method of authentication on the internet. However, static password is used in conventional password authentication scheme. Therefore, attackers may impersonate a regular user with replay or guessing attack. For this reason, user authentication system with OTP (One-Time Password) has been proposed. Authentication systems of one-time password change the verifier every time by sending the present verifier along with the next verifier. Therefore, attackers can not impersonate a regular user with verifier which had been used. There are two kinds of password, weak password and strong password. Weak password which user is used to choosing easy to remember password, can not resist guessing attack. A strong password means that it is well-chosen, confused and hard to guess. Strong password is too hard to remember. Therefore, strong password must store in tamper-resistant hardware device, such as smart card. In 1981, Lamport first proposed a one-time password method based on low-computation hash functions, but this method has problems. For solving these problems, many one-time password authentication methods have been proposed, such as S/KEY, CINON. Before, one-time password method do not force user to use strong password, thus these methods are unable to resist brute-force and guessing attacks. Till now, many one-time password authentication methods have been proposed with strong password. These methods can resist brute-force and guessing attacks, but none of them can resist all well-known attacks, such as man in the middle, impersonate and stolen verifier attacks. In this thesis, we will review one-time password methods. Then, we propose a secure and low-computation one-time password method that can resist all well known attacks. Finally, we will implement this method with smart card. Chun-Li Lin 林峻立 2005 學位論文 ; thesis 66 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 樹德科技大學 === 資訊工程學系 === 94 === In the internet environment, user authentication is very important. Server can avoid illegal user with user authentication. A password-based scheme is the most generally used method of authentication on the internet. However, static password is used in conventional password authentication scheme. Therefore, attackers may impersonate a regular user with replay or guessing attack. For this reason, user authentication system with OTP (One-Time Password) has been proposed. Authentication systems of one-time password change the verifier every time by sending the present verifier along with the next verifier. Therefore, attackers can not impersonate a regular user with verifier which had been used.
There are two kinds of password, weak password and strong password. Weak password which user is used to choosing easy to remember password, can not resist guessing attack. A strong password means that it is well-chosen, confused and hard to guess. Strong password is too hard to remember. Therefore, strong password must store in tamper-resistant hardware device, such as smart card.
In 1981, Lamport first proposed a one-time password method based on low-computation hash functions, but this method has problems. For solving these problems, many one-time password authentication methods have been proposed, such as S/KEY, CINON. Before, one-time password method do not force user to use strong password, thus these methods are unable to resist brute-force and guessing attacks. Till now, many one-time password authentication methods have been proposed with strong password. These methods can resist brute-force and guessing attacks, but none of them can resist all well-known attacks, such as man in the middle, impersonate and stolen verifier attacks.
In this thesis, we will review one-time password methods. Then, we propose a secure and low-computation one-time password method that can resist all well known attacks. Finally, we will implement this method with smart card.
|
author2 |
Chun-Li Lin |
author_facet |
Chun-Li Lin Chiang-Jiun Shie 謝鉛俊 |
author |
Chiang-Jiun Shie 謝鉛俊 |
spellingShingle |
Chiang-Jiun Shie 謝鉛俊 Research and Implementation of One-Time Password Authentication |
author_sort |
Chiang-Jiun Shie |
title |
Research and Implementation of One-Time Password Authentication |
title_short |
Research and Implementation of One-Time Password Authentication |
title_full |
Research and Implementation of One-Time Password Authentication |
title_fullStr |
Research and Implementation of One-Time Password Authentication |
title_full_unstemmed |
Research and Implementation of One-Time Password Authentication |
title_sort |
research and implementation of one-time password authentication |
publishDate |
2005 |
url |
http://ndltd.ncl.edu.tw/handle/66641148672866986409 |
work_keys_str_mv |
AT chiangjiunshie researchandimplementationofonetimepasswordauthentication AT xièqiānjùn researchandimplementationofonetimepasswordauthentication AT chiangjiunshie yīcìxìngtōngxíngmǎrènzhèngzhīyánjiūyǔshízuò AT xièqiānjùn yīcìxìngtōngxíngmǎrènzhèngzhīyánjiūyǔshízuò |
_version_ |
1718287448383946752 |