A unidirectional one-time password authentication scheme without counter desynchronization
Shuren Liao, Qiuyan Zhang, Chao Chen, Yiqi Dai · 2009
As a primary mean of authentication, static password based authentication methods suffer from high risk in current insecure network environment. The one-time password (OTP) authentication scheme is proposed to efficiently resist the replay attack and the guessing attack. However, current one-time password schemes bring new problems. The OTP schemes of challenge-response are hard to integrate into most of the existing authentication infrastructures, while others suffer the counter desynchronization problem, which results in failed authentication of a legitimate user. In this paper we propose a novel OTP scheme. The new scheme preserves security property of current schemes, and is free from counter desynchronization. Meanwhile, the scheme can be easily deployed in the current authentication system.