• DocumentCode
    2730257
  • Title

    Design of a time and location based One-Time Password authentication scheme

  • Author

    Hsieh, Wen-Bin ; Leu, Jenq-Shiou

  • Author_Institution
    Dept. of Electron. Eng., Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
  • fYear
    2011
  • fDate
    4-8 July 2011
  • Firstpage
    201
  • Lastpage
    206
  • Abstract
    As the mobile networks are springing up, mobile devices become a must gadget in our daily life. People can easily access Internet application services anytime and anywhere via the hand-carried mobile devices. Most of modern mobile devices are equipped with a GPS module, which can help get the real-time location of the mobile device. In this paper, we propose a novel authentication scheme which exploits volatile passwords - One-Time Passwords (OTPs) based on the time and location information of the mobile device to transparently and securely authenticate users while accessing Internet services, such as online banking services and e-commerce transactions. Compared to a permanent password base scheme, an OTP based one can prevent users from being eavesdropped. In addition to a memoryless feature, the scheme restricts the validness of the OTP password not only in a certain time period but also in a tolerant geometric region to increase the security protection. However, if a legitimate user is not in the anticipated tolerant region, the user may fail to be authenticated. Hence, a Short Message Service (SMS) based mutual authentication mechanism is also proposed in the article to supplement the unexpected misjudgement. The proposed method with a volatile time/location-based password features more secure and more convenient for user authentication.
  • Keywords
    Internet; authorisation; mobile computing; Internet application services; Internet services; e-commerce transactions; location based one-time password authentication scheme; mobile devices; mobile networks; mutual authentication; online banking services; security protection; short message service; time based one-time password authentication scheme; volatile passwords; Authentication; Cryptography; Global Positioning System; Mobile communication; Mobile handsets; Servers; GPS; Mutual Authentication; One-Time Passwords; Time and Location Based Authentication; Volatile Authentication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Wireless Communications and Mobile Computing Conference (IWCMC), 2011 7th International
  • Conference_Location
    Istanbul
  • Print_ISBN
    978-1-4244-9539-9
  • Type

    conf

  • DOI
    10.1109/IWCMC.2011.5982418
  • Filename
    5982418