• DocumentCode
    1972825
  • Title

    Two factor authentication using mobile phones

  • Author

    Aloul, Fadi ; Zahidi, Syed ; El-Hajj, Wassim

  • Author_Institution
    Dept. of Comput. Sci. & Eng., American Univ. of Sharjah, Sharjah
  • fYear
    2009
  • fDate
    10-13 May 2009
  • Firstpage
    641
  • Lastpage
    644
  • Abstract
    This paper describes a method of implementing two factor authentication using mobile phones. The proposed method guarantees that authenticating to services, such as online banking or ATM machines, is done in a very secure manner. The proposed system involves using a mobile phone as a software token for one time password generation. The generated one time password is valid for only a short user-defined period of time and is generated by factors that are unique to both, the user and the mobile device itself. Additionally, an SMS-based mechanism is implemented as both a backup mechanism for retrieving the password and as a possible mean of synchronization. The proposed method has been implemented and tested. Initial results show the success of the proposed method.
  • Keywords
    electronic messaging; message authentication; mobile computing; mobile handsets; synchronisation; SMS-based mechanism; mobile phone; one time password generation; software token; synchronization; two factor authentication; Authentication; Banking; Computer hacking; Costs; Educational institutions; GSM; Mobile communication; Mobile handsets; Security; System testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Systems and Applications, 2009. AICCSA 2009. IEEE/ACS International Conference on
  • Conference_Location
    Rabat
  • Print_ISBN
    978-1-4244-3807-5
  • Electronic_ISBN
    978-1-4244-3806-8
  • Type

    conf

  • DOI
    10.1109/AICCSA.2009.5069395
  • Filename
    5069395