DocumentCode :
2820367
Title :
A Design of One-Time Password Mechanism Using Public Key Infrastructure
Author :
Kim, Hyun-Chul ; Lee, Hyang-Won ; Lee, Kyung-Seok ; Jun, Moon-Seog
Author_Institution :
Dept. of Comput. Sci., SoongSil Univ., Seoul
Volume :
1
fYear :
2008
fDate :
2-4 Sept. 2008
Firstpage :
18
Lastpage :
24
Abstract :
One-time password mechanism solves password problems like password conjecture and wiretapping that can occur by using the same password several times repeatedly. However, such one-time password mechanism also is exposed to various attacks, and is vulnerable in matters of confidentiality and security protection, the most important elements of security depending on mechanism. This paper solves user disguise problem by authenticating users with the use of public key infrastructure, and guarantees integrity by generating password by applying session identifier L and random value R to hash function in every applicable session. Additionally, to enhance security while transferring the generated password, the mechanism digital signature the password with user´s private key, encode it again with service provider´s public key, and guarantee denial prevention by requesting the server authentication while being able to verify the identity of user. Therefore in this paper proposes one-time password mechanism that has enhanced security using public key infrastructure to prevent integrity problem due to birthday attack and hash collision problem occurring from hash function. Comparison and analysis of existing one-time password mechanism will tell of the excellence of this paper.
Keywords :
digital signatures; public key cryptography; birthday attack; digital signature; hash collision; hash function; one-time password mechanism; public key infrastructure; random value; server authentication; session identifier; user disguise; Authentication; Computer networks; Computer science; Information management; Information security; Java; Network servers; Protection; Public key; Web server; Certificate; One-time password; PKI;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Networked Computing and Advanced Information Management, 2008. NCM '08. Fourth International Conference on
Conference_Location :
Gyeongju
Print_ISBN :
978-0-7695-3322-3
Type :
conf
DOI :
10.1109/NCM.2008.77
Filename :
4623971
Link To Document :
بازگشت