DocumentCode
434539
Title
The N/R one time password system
Author
Goyal, Vipul ; Abraham, Ajith ; Sanyal, Sugata ; Han, Sang Yong
Author_Institution
OSP Global, Mumbai, India
Volume
1
fYear
2005
fDate
4-6 April 2005
Firstpage
733
Abstract
A new one time password system is described which is secure against eavesdropping and server database compromise at the same time. Traditionally, these properties have proven to be difficult to satisfy at the same time and only one previous scheme i.e. Lamport hashes also called S/KEY one time password system has claimed to achieve that. Lamport hashes however have a limitation that they are computationally intensive for the client and the number of times a client may login before the system should be re-initialized is small. We address these limitations to come up with a new scheme called the N/R one time password system. The basic idea is have the server aid the client computation by inserting ´breakpoints´ in the hash chains. Client computational requirements are dramatically reduced without any increase in the server computational requirements and the number of times a client may login before the system has to be reinitialized is also increased significantly. The system is particularly suited for mobile and constrained devices having limited computational power.
Keywords
authorisation; client-server systems; message authentication; public key cryptography; N-R one time password system; authorisation; client computational requirements; client-server systems; hash chains; message authentication; public key cryptography; server computational requirements; server database; Computer networks; Computer science; Data engineering; Databases; Explosions; Explosives; IP networks; Mission critical systems; Mobile computing; Network servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Technology: Coding and Computing, 2005. ITCC 2005. International Conference on
Print_ISBN
0-7695-2315-3
Type
conf
DOI
10.1109/ITCC.2005.275
Filename
1428551
Link To Document