Analysis of Vulnerabilities That Can Occur When Generating One-Time Password

Analysis of Vulnerabilities That Can Occur When Generating One-Time Password
复制标题

生成一次性密码时可能出现的漏洞分析

DOI:
--
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Okyeon Yi
Okyeon Yi
中科院分区:
--
文献类型:
--
作者:
Hyunki Kim;Juhong Han;Chanil Park;Okyeon Yi

文献摘要

被引文献

相似文献

一次性密码(OTP)是指在IT系统或数字设备中仅对一次登录会话或事务有效的密码。这是以人为中心的安全服务之一,通常用于多因素身份验证。这非常类似于在密码学中生成伪随机比特流。但是,它只是比特流中用作动态口令的一部分。因此,动态口令机制需要一种算法来提取部分。还需要将十六进制转换为十进制,以便人类熟悉位串的值。在本文中,我们分类了三种从伪随机位序列中提取最终数据的算法。我们还分析了在提取过程中出现漏洞的事实,即使使用了加密安全的生成算法,也会导致某些数字出现的频率很高。
A one-time password (OTP) is a password that is valid for only one login session or transaction, in IT systems or digital devices. This is one of the human-centered security services and is commonly used for multi-factor authentication. This is very similar to generating pseudo-random bit streams in cryptography. However, it is only part of what is used as OTP in the bit stream. Therefore, the OTP mechanism requires an algorithm to extract portions. It is also necessary to convert hexadecimal to decimal so that the values of the bit strings are familiar to human. In this paper, we classify three algorithms for extracting the final data from the pseudo random bit sequence. We also analyze the fact that a vulnerability occurs during the extraction process, resulting in a high frequency of certain numbers; even if cryptographically secure generation algorithms are used.