DocumentCode
2820367
Title
A Design of One-Time Password Mechanism Using Public Key Infrastructure
Author
Kim, Hyun-Chul ; Lee, Hyang-Won ; Lee, Kyung-Seok ; Jun, Moon-Seog
Author_Institution
Dept. of Comput. Sci., SoongSil Univ., Seoul
Volume
1
fYear
2008
fDate
2-4 Sept. 2008
Firstpage
18
Lastpage
24
Abstract
One-time password mechanism solves password problems like password conjecture and wiretapping that can occur by using the same password several times repeatedly. However, such one-time password mechanism also is exposed to various attacks, and is vulnerable in matters of confidentiality and security protection, the most important elements of security depending on mechanism. This paper solves user disguise problem by authenticating users with the use of public key infrastructure, and guarantees integrity by generating password by applying session identifier L and random value R to hash function in every applicable session. Additionally, to enhance security while transferring the generated password, the mechanism digital signature the password with user´s private key, encode it again with service provider´s public key, and guarantee denial prevention by requesting the server authentication while being able to verify the identity of user. Therefore in this paper proposes one-time password mechanism that has enhanced security using public key infrastructure to prevent integrity problem due to birthday attack and hash collision problem occurring from hash function. Comparison and analysis of existing one-time password mechanism will tell of the excellence of this paper.
Keywords
digital signatures; public key cryptography; birthday attack; digital signature; hash collision; hash function; one-time password mechanism; public key infrastructure; random value; server authentication; session identifier; user disguise; Authentication; Computer networks; Computer science; Information management; Information security; Java; Network servers; Protection; Public key; Web server; Certificate; One-time password; PKI;
fLanguage
English
Publisher
ieee
Conference_Titel
Networked Computing and Advanced Information Management, 2008. NCM '08. Fourth International Conference on
Conference_Location
Gyeongju
Print_ISBN
978-0-7695-3322-3
Type
conf
DOI
10.1109/NCM.2008.77
Filename
4623971
Link To Document