bOTP: Two-Factor based Unpredictable OTP using the Hash of Latest Block of the Ethereum Blockchain
Abstract
A service providing server seeks to achieve enhanced security by requesting the user for presenting an OTP value before executing a critical transaction such as money transfer. The OTP method by a separate token-type battery-powered device is not expected to always work due to the limited battery lifetime of the device, and when a problem occurs, it needs to be replaced for a fee. Other method of generating OTP by executing a mobile app is useful because no separate device is required, but it does not provide the security of the level of two-factor authentication. We propose an OTP scheme that uses the latest block of the Ethereum blockchain to generate and verify unpredictable OTPs by referring to a secret value within a mobile app and other secret stored on a separate media such as a paper. The proposed scheme achieves the high security of dual-factor authentication at no additional cost, without expiration of validity, while ensuring the currency and unpredictability of the generated OTP. Therefore, the introduction of the proposed scheme makes it possible to force the use of OTP in more diverse areas, which can add additional security to various authentication such as passwords, smart keys, and biometric recognition. As a result, it is expected that strengthened authentication can be applied without separate equipment, infrastructure, or cost, which will greatly contribute to the revitalization of Internet commerce and the creation of new business models relied on strong security for user authentication.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.