Research and Implementation of One-Time Password Authentication

碩士 === 樹德科技大學 === 資訊工程學系 === 94 === In the internet environment, user authentication is very important. Server can avoid illegal user with user authentication. A password-based scheme is the most generally used method of authentication on the internet. However, static password is used in conventiona...

Full description

Bibliographic Details
Main Authors: Chiang-Jiun Shie, 謝鉛俊
Other Authors: Chun-Li Lin
Format: Others
Language:zh-TW
Published: 2005
Online Access:http://ndltd.ncl.edu.tw/handle/66641148672866986409
id ndltd-TW-094STU00392010
record_format oai_dc
spelling ndltd-TW-094STU003920102016-06-01T04:14:43Z http://ndltd.ncl.edu.tw/handle/66641148672866986409 Research and Implementation of One-Time Password Authentication 一次性通行碼認證之研究與實作 Chiang-Jiun Shie 謝鉛俊 碩士 樹德科技大學 資訊工程學系 94 In the internet environment, user authentication is very important. Server can avoid illegal user with user authentication. A password-based scheme is the most generally used method of authentication on the internet. However, static password is used in conventional password authentication scheme. Therefore, attackers may impersonate a regular user with replay or guessing attack. For this reason, user authentication system with OTP (One-Time Password) has been proposed. Authentication systems of one-time password change the verifier every time by sending the present verifier along with the next verifier. Therefore, attackers can not impersonate a regular user with verifier which had been used.   There are two kinds of password, weak password and strong password. Weak password which user is used to choosing easy to remember password, can not resist guessing attack. A strong password means that it is well-chosen, confused and hard to guess. Strong password is too hard to remember. Therefore, strong password must store in tamper-resistant hardware device, such as smart card.   In 1981, Lamport first proposed a one-time password method based on low-computation hash functions, but this method has problems. For solving these problems, many one-time password authentication methods have been proposed, such as S/KEY, CINON. Before, one-time password method do not force user to use strong password, thus these methods are unable to resist brute-force and guessing attacks. Till now, many one-time password authentication methods have been proposed with strong password. These methods can resist brute-force and guessing attacks, but none of them can resist all well-known attacks, such as man in the middle, impersonate and stolen verifier attacks.   In this thesis, we will review one-time password methods. Then, we propose a secure and low-computation one-time password method that can resist all well known attacks. Finally, we will implement this method with smart card. Chun-Li Lin 林峻立 2005 學位論文 ; thesis 66 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 樹德科技大學 === 資訊工程學系 === 94 === In the internet environment, user authentication is very important. Server can avoid illegal user with user authentication. A password-based scheme is the most generally used method of authentication on the internet. However, static password is used in conventional password authentication scheme. Therefore, attackers may impersonate a regular user with replay or guessing attack. For this reason, user authentication system with OTP (One-Time Password) has been proposed. Authentication systems of one-time password change the verifier every time by sending the present verifier along with the next verifier. Therefore, attackers can not impersonate a regular user with verifier which had been used.   There are two kinds of password, weak password and strong password. Weak password which user is used to choosing easy to remember password, can not resist guessing attack. A strong password means that it is well-chosen, confused and hard to guess. Strong password is too hard to remember. Therefore, strong password must store in tamper-resistant hardware device, such as smart card.   In 1981, Lamport first proposed a one-time password method based on low-computation hash functions, but this method has problems. For solving these problems, many one-time password authentication methods have been proposed, such as S/KEY, CINON. Before, one-time password method do not force user to use strong password, thus these methods are unable to resist brute-force and guessing attacks. Till now, many one-time password authentication methods have been proposed with strong password. These methods can resist brute-force and guessing attacks, but none of them can resist all well-known attacks, such as man in the middle, impersonate and stolen verifier attacks.   In this thesis, we will review one-time password methods. Then, we propose a secure and low-computation one-time password method that can resist all well known attacks. Finally, we will implement this method with smart card.
author2 Chun-Li Lin
author_facet Chun-Li Lin
Chiang-Jiun Shie
謝鉛俊
author Chiang-Jiun Shie
謝鉛俊
spellingShingle Chiang-Jiun Shie
謝鉛俊
Research and Implementation of One-Time Password Authentication
author_sort Chiang-Jiun Shie
title Research and Implementation of One-Time Password Authentication
title_short Research and Implementation of One-Time Password Authentication
title_full Research and Implementation of One-Time Password Authentication
title_fullStr Research and Implementation of One-Time Password Authentication
title_full_unstemmed Research and Implementation of One-Time Password Authentication
title_sort research and implementation of one-time password authentication
publishDate 2005
url http://ndltd.ncl.edu.tw/handle/66641148672866986409
work_keys_str_mv AT chiangjiunshie researchandimplementationofonetimepasswordauthentication
AT xièqiānjùn researchandimplementationofonetimepasswordauthentication
AT chiangjiunshie yīcìxìngtōngxíngmǎrènzhèngzhīyánjiūyǔshízuò
AT xièqiānjùn yīcìxìngtōngxíngmǎrènzhèngzhīyánjiūyǔshízuò
_version_ 1718287448383946752