DocumentCode :
113952
Title :
Time-based OTP authentication via secure tunnel (TOAST): A mobile TOTP scheme using TLS seed exchange and encrypted offline keystore
Author :
Uymatiao, Mariano Luis T. ; Yu, William Emmanuel S.
Author_Institution :
Dept. of Inf. Syst. & Comput. Sci., Ateneo de Manila Univ., Quezon City, Philippines
fYear :
2014
fDate :
26-28 April 2014
Firstpage :
225
Lastpage :
229
Abstract :
The main objective of this research is to build upon existing cryptographic standards and web protocols to design an alternative multi-factor authentication cryptosystem for the web. It involves seed exchange to a software-based token through a login-protected Transport Layer Security (TLS/SSL) tunnel, encrypted local storage through a password-protected keystore (BC UBER) with a strong key derivation function (PBEWithSHAANDTwofish-CBC), and offline generation of one-time passwords through the TOTP algorithm (IETF RFC 6239). Authentication occurs through the use of a shared secret (the seed) to verify the correctness of the one-time password used to authenticate. With the traditional use of username and password no longer wholly adequate for protecting online accounts, and with regulators worldwide toughening up security requirements (i.e. BSP 808, FFIEC), this research hopes to increase research effort on further development of cryptosystems involving multi-factor authentication.
Keywords :
authorisation; cryptography; BC UBER keystore; IETF RFC 6239 standard; PBEWithSHAANDTwofish-CBC function; TLS seed exchange; TOAST scheme; TOTP algorithm; Web protocols; cryptographic standards; cryptosystems development; encrypted offline keystore; mobile TOTP scheme; multifactor authentication; multifactor authentication cryptosystem; one-time password; password-protected keystore; secure tunnel; security requirements; software-based token; strong key derivation function; time-based OTP authentication; transport layer security; Authentication; Cryptography; Google; Mobile communication; Radiation detectors; Servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Science and Technology (ICIST), 2014 4th IEEE International Conference on
Conference_Location :
Shenzhen
Type :
conf
DOI :
10.1109/ICIST.2014.6920371
Filename :
6920371
Link To Document :
بازگشت