Skip to main content
Erschienen in: Mobile Networks and Applications 5/2013

01.10.2013

Ubiquitous One-Time Password Service Using the Generic Authentication Architecture

verfasst von: Chunhua Chen, Chris J. Mitchell, Shaohua Tang

Erschienen in: Mobile Networks and Applications | Ausgabe 5/2013

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The Generic Authentication Architecture (GAA) is a standardised extension to the mobile authentication infrastructure that enables the provision of security services, such as key establishment, to network applications. In this paper we first show how Trusted Computing can be extended in a GAA-like framework to offer new security services. We then propose a general scheme that converts a simple static password authentication mechanism into a one-time password (OTP) system using the GAA key establishment service. The scheme employs a GAA-enabled user device and a GAA-aware server. Most importantly, unlike most OTP systems using a dedicated key-bearing token, the user device does not need to be user or server specific, and can be used in the protocol with no registration or configuration (except for the installation of the necessary application software). We also give two practical instantiations of the general scheme, building firstly on the mobile authentication infrastructure and secondly on Trusted Computing. The practical systems are secure, scalable, fit well to the multi-institution scenario, and enable the provision of ubiquitous and on-demand OTP services.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Weitere Produktempfehlungen anzeigen
Fußnoten
1
The 3rd Generation Partnership Project (3GPP).
 
2
The 3rd Generation Partnership Project 2 (3GPP2).
 
3
In the GAA specifications [5], the functionality of a GAA-aware application server is referred to as the Network Application Function (NAF).
 
Literatur
1.
Zurück zum Zitat 3rd Generation Partnership Project (3GPP) (2009) 3G security: access secure for IP-based services. Technical Specification TS 33.203, version 9.3.0 3rd Generation Partnership Project (3GPP) (2009) 3G security: access secure for IP-based services. Technical Specification TS 33.203, version 9.3.0
2.
Zurück zum Zitat 3rd Generation Partnership Project (3GPP) (2009) Bootstrapping interface (Ub) and network application function interface (Ua); Protocol details. Technical Specification TS 24.109, version 9.1.0 3rd Generation Partnership Project (3GPP) (2009) Bootstrapping interface (Ub) and network application function interface (Ua); Protocol details. Technical Specification TS 24.109, version 9.1.0
3.
Zurück zum Zitat 3rd Generation Partnership Project (3GPP) (2009) Generic authentication architecture (GAA); access to network application functions using hypertext transfer protocol over transport layer security (HTTPS). Technical Specification TS 33.222, version 9.1.0 3rd Generation Partnership Project (3GPP) (2009) Generic authentication architecture (GAA); access to network application functions using hypertext transfer protocol over transport layer security (HTTPS). Technical Specification TS 33.222, version 9.1.0
4.
Zurück zum Zitat 3rd Generation Partnership Project (3GPP) (2009) Numbering, addressing and identification. Technical Specification TS 23.003, version 9.2.0 3rd Generation Partnership Project (3GPP) (2009) Numbering, addressing and identification. Technical Specification TS 23.003, version 9.2.0
5.
Zurück zum Zitat 3rd Generation Partnership Project (3GPP) (2009) Technical specification group services and systems aspects, generic authentication architecture (GAA), generic bootstrapping architecture. Technical Specification TS 33.220, version 9.2.0 3rd Generation Partnership Project (3GPP) (2009) Technical specification group services and systems aspects, generic authentication architecture (GAA), generic bootstrapping architecture. Technical Specification TS 33.220, version 9.2.0
6.
Zurück zum Zitat Alzomai M, Josang A (2010) The mobile phone as a multi OTP device using trusted computing. In: Proceedings of the 4th international conference on network and system security. IEEE Computer Society, Melbourne, Australia, pp 75–82 Alzomai M, Josang A (2010) The mobile phone as a multi OTP device using trusted computing. In: Proceedings of the 4th international conference on network and system security. IEEE Computer Society, Melbourne, Australia, pp 75–82
7.
Zurück zum Zitat Boyd C, Mathuria A (2003) Protocols for authentication and key establishment. Springer Boyd C, Mathuria A (2003) Protocols for authentication and key establishment. Springer
8.
9.
Zurück zum Zitat Franks J, Hallam-Baker PM, Hostetler JL, Lawrence SD, Leach PJ, Luotonen A, Stewart LC (1999) HTTP authentication: basic and digest access authentication. Internet Engineering Task Force, RFC 2617 Franks J, Hallam-Baker PM, Hostetler JL, Lawrence SD, Leach PJ, Luotonen A, Stewart LC (1999) HTTP authentication: basic and digest access authentication. Internet Engineering Task Force, RFC 2617
11.
Zurück zum Zitat Holtmanns S, Niemi V, Ginzboorg P, Laitinen P, Asokan N (2008) Cellular authentication for mobile and internet services. John Wiley and Sons Holtmanns S, Niemi V, Ginzboorg P, Laitinen P, Asokan N (2008) Cellular authentication for mobile and internet services. John Wiley and Sons
12.
Zurück zum Zitat International Organization for Standardization (1998) ISO/IEC 9798-3:1998/Amd 1:2010, information technology—security techniques—entity authentication—part 3: mechanisms using digital signature techniques. Genève, Switzerland International Organization for Standardization (1998) ISO/IEC 9798-3:1998/Amd 1:2010, information technology—security techniques—entity authentication—part 3: mechanisms using digital signature techniques. Genève, Switzerland
13.
Zurück zum Zitat James L (2006) Phishing exposed. Syngress James L (2006) Phishing exposed. Syngress
14.
Zurück zum Zitat Krawczyk H, Bellare M, Canetti R (1997) HMAC: Keyed-hashing for message authentication. Internet Engineering Task Force, RFC 2104 (Informational) Krawczyk H, Bellare M, Canetti R (1997) HMAC: Keyed-hashing for message authentication. Internet Engineering Task Force, RFC 2104 (Informational)
15.
Zurück zum Zitat Molva R, Tsudik G (1993) Authentication method with impersonal token cards. In: Proceedings of the 1993 IEEE symposium on security and privacy. IEEE Computer Society, Oakland, California, USA, pp 56–65CrossRef Molva R, Tsudik G (1993) Authentication method with impersonal token cards. In: Proceedings of the 1993 IEEE symposium on security and privacy. IEEE Computer Society, Oakland, California, USA, pp 56–65CrossRef
16.
Zurück zum Zitat M’Raihi D, Bellare M, Hoornaert F, Naccache D, Ranen O (2005) HOTP: an HMAC-based one-time password algorithm. Internet Engineering Task Force, RFC 4226 (Informational) M’Raihi D, Bellare M, Hoornaert F, Naccache D, Ranen O (2005) HOTP: an HMAC-based one-time password algorithm. Internet Engineering Task Force, RFC 4226 (Informational)
18.
Zurück zum Zitat Trusted Computing Group (2007) TCG mobile reference architecture, TCG Specification, Version 1.0, Revision 1 Trusted Computing Group (2007) TCG mobile reference architecture, TCG Specification, Version 1.0, Revision 1
19.
Zurück zum Zitat Trusted Computing Group (2007) TPM main, part 1 design principles. TCG Specification, Version 1.2, Revision 103 Trusted Computing Group (2007) TPM main, part 1 design principles. TCG Specification, Version 1.2, Revision 103
20.
Zurück zum Zitat Trusted Computing Group (2007) TPM main, part 2 TPM data structures. TCG Specification, Version 1.2, Revision 103 Trusted Computing Group (2007) TPM main, part 2 TPM data structures. TCG Specification, Version 1.2, Revision 103
21.
Zurück zum Zitat Trusted Computing Group (2007) TPM main, part 3 commands. TCG Specification, Version 1.2, Revision 103 Trusted Computing Group (2007) TPM main, part 3 commands. TCG Specification, Version 1.2, Revision 103
22.
Zurück zum Zitat Trusted Computing Group (2010) TCG mobile trusted module specification. TCG Specification, Version 1.0, Revision 7.02 Trusted Computing Group (2010) TCG mobile trusted module specification. TCG Specification, Version 1.0, Revision 7.02
Metadaten
Titel
Ubiquitous One-Time Password Service Using the Generic Authentication Architecture
verfasst von
Chunhua Chen
Chris J. Mitchell
Shaohua Tang
Publikationsdatum
01.10.2013
Verlag
Springer US
Erschienen in
Mobile Networks and Applications / Ausgabe 5/2013
Print ISSN: 1383-469X
Elektronische ISSN: 1572-8153
DOI
https://doi.org/10.1007/s11036-011-0329-z

Weitere Artikel der Ausgabe 5/2013

Mobile Networks and Applications 5/2013 Zur Ausgabe

Neuer Inhalt