详细信息
An Efficient Two-Factor Authentication Scheme Based on the Merkle Tree ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:An Efficient Two-Factor Authentication Scheme Based on the Merkle Tree
作者:Yin, Xinming[1,2];He, Junhui[3];Guo, Yi[1];Han, Dezhi[3];Li, Kuan-Ching[4,5];Castiglione, Arcangelo[6]
机构:[1]East China Univ Sci & Technol, Dept Comp Sci & Engn, 130 Meilong Rd, Shanghai 200237, Peoples R China;[2]Minist Publ Secur, Res Inst 3, 76 Yueyang Rd, Shanghai 200031, Peoples R China;[3]Shanghai Maritime Univ, Coll Informat Engn, Shanghai 201306, Peoples R China;[4]Providence Univ, Dept Comp Sci & Informat Engn CSIE, Taichung 43301, Taiwan;[5]Anhui Univ Sci & Technol, Sch Comp Sci & Engn, Huainan 232001, Peoples R China;[6]Univ Salerno, Dept Comp Sci, I-84084 Fisciano, Italy
年份:2020
卷号:20
期号:20
起止页码:1
外文期刊名:SENSORS
收录:;EI(收录号:20204209349807);WOS:【SCI-EXPANDED(收录号:WOS:000585685900001)】;
基金:This research was funded by The National Key Research and Development Program of China (Grant Numbers 2018YFC0807105, 2018YFC0807106) and the Shanghai Science and Technology Talent Program (Grant Number 17XD1420400).
语种:英文
外文关键词:one-time password; two-factor authentication; hash chain; Merkle tree
摘要:The Time-based One-Time Password (TOTP) algorithm is commonly used for two-factor authentication. In this algorithm, a shared secret is used to derive a One-Time Password (OTP). However, in TOTP, the client and the server need to agree on a shared secret (i.e., a key). As a consequence, an adversary can construct an OTP through the compromised key if the server is hacked. To solve this problem, Kogan et al. proposed T/Key, an OTP algorithm based on a hash chain. However, the efficiency of OTP generation and verification is low in T/Key. In this article, we propose a novel and efficient Merkle tree-based One-Time Password (MOTP) algorithm to overcome such limitations. Compared to T/Key, this proposal reduces the number of hash operations to generate and verify the OTP, at the cost of small server storage and tolerable client storage. Experimental analysis and security evaluation show that MOTP can resist leakage attacks against the server and bring a tiny delay to two-factor authentication and verification time.
参考文献:
正在载入数据...
