OTP-Based Transaction Verification Protocol Using PUFs 


Vol. 38,  No. 6, pp. 492-500, Jun.  2013


PDF
  Abstract

The One-Time Password(OTP) Generator is used as a multi-factor authentication method to ensure secure transaction during e-Financial transaction in the bank and securities company. The OTP based e-Financial Transaction Verification Protocol ensures secure e-financial transaction through confirming the user"s identity using OTP authentication information and counters not only Man-in-the-Browser(MITB) attacks but also memory hacking attacks. However, it is possible to generate correct OTPs due to potential of stealing sensitive information of the OTP generator through intelligent phishing, pharming, social engineering attacks. Therefore, it needs another scheme to prevent from above threats, and this paper proposes advanced scheme using Physical Unclonable Functions(PUFs) to solve these problems. First, it is impossible to generate the same OTP values because of the hysically unclonable features of PUFs. In addition, it is impossible to clone OTP generator with hardware techniques. Consequently, the proposed protocol provides stronger and more robust authentication protocol than existing one by adding PUFs in the OTP generator.

  Statistics
Cumulative Counts from November, 2022
Multiple requests among the same browser session are counted as one view. If you mouse over a chart, the values of data points will be shown.


  Cite this article

[IEEE Style]

J. Lee, M. Park*, S. Jung, "OTP-Based Transaction Verification Protocol Using PUFs," The Journal of Korean Institute of Communications and Information Sciences, vol. 38, no. 6, pp. 492-500, 2013. DOI: .

[ACM Style]

Jonghoon Lee, Minho Park*, and Souhwan Jung. 2013. OTP-Based Transaction Verification Protocol Using PUFs. The Journal of Korean Institute of Communications and Information Sciences, 38, 6, (2013), 492-500. DOI: .

[KICS Style]

Jonghoon Lee, Minho Park*, Souhwan Jung, "OTP-Based Transaction Verification Protocol Using PUFs," The Journal of Korean Institute of Communications and Information Sciences, vol. 38, no. 6, pp. 492-500, 6. 2013.