A secure one-time password authentication scheme using smart cards without limiting login times
Ya‐Fen Chang, Chin‐Chen Chang, Jui-Yi Kuo · ACM SIGOPS Operating Systems Review · 2004
With the one-time password concept, the S/Key scheme is widely utilized by the protocols with limited login times to defend against replay attack. By employing the simple and unidirectional hash function, the improved version of the S/Key scheme is proposed to withstand spoofing attack, pre-play attack and off-line dictionary attack. However, the schemes limit login times. Hence, we propose a scheme, preserving the same properties and withstanding the stolen-verifier attack, without limiting the login times.