详细信息

An Efficient Two-Factor Authentication Scheme Based on the Merkle Tree  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:An Efficient Two-Factor Authentication Scheme Based on the Merkle Tree

作者:Yin, Xinming[1,2];He, Junhui[3];Guo, Yi[1];Han, Dezhi[3];Li, Kuan-Ching[4,5];Castiglione, Arcangelo[6]

机构:[1]East China Univ Sci & Technol, Dept Comp Sci & Engn, 130 Meilong Rd, Shanghai 200237, Peoples R China;[2]Minist Publ Secur, Res Inst 3, 76 Yueyang Rd, Shanghai 200031, Peoples R China;[3]Shanghai Maritime Univ, Coll Informat Engn, Shanghai 201306, Peoples R China;[4]Providence Univ, Dept Comp Sci & Informat Engn CSIE, Taichung 43301, Taiwan;[5]Anhui Univ Sci & Technol, Sch Comp Sci & Engn, Huainan 232001, Peoples R China;[6]Univ Salerno, Dept Comp Sci, I-84084 Fisciano, Italy

年份:2020

卷号:20

期号:20

起止页码:1

外文期刊名:SENSORS

收录:;EI(收录号:20204209349807);WOS:【SCI-EXPANDED(收录号:WOS:000585685900001)】;

基金:This research was funded by The National Key Research and Development Program of China (Grant Numbers 2018YFC0807105, 2018YFC0807106) and the Shanghai Science and Technology Talent Program (Grant Number 17XD1420400).

语种:英文

外文关键词:one-time password; two-factor authentication; hash chain; Merkle tree

摘要:The Time-based One-Time Password (TOTP) algorithm is commonly used for two-factor authentication. In this algorithm, a shared secret is used to derive a One-Time Password (OTP). However, in TOTP, the client and the server need to agree on a shared secret (i.e., a key). As a consequence, an adversary can construct an OTP through the compromised key if the server is hacked. To solve this problem, Kogan et al. proposed T/Key, an OTP algorithm based on a hash chain. However, the efficiency of OTP generation and verification is low in T/Key. In this article, we propose a novel and efficient Merkle tree-based One-Time Password (MOTP) algorithm to overcome such limitations. Compared to T/Key, this proposal reduces the number of hash operations to generate and verify the OTP, at the cost of small server storage and tolerable client storage. Experimental analysis and security evaluation show that MOTP can resist leakage attacks against the server and bring a tiny delay to two-factor authentication and verification time.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心