Anusorn Kanyaprasankid. Generating one-time password by web-based technology-new approach for authentication on web-based service. Master's Degree(Technology of Information System Management). Mahidol University. : Mahidol University, 2009-06-30.
Generating one-time password by web-based technology-new approach for authentication on web-based service
Abstract:
The purpose of this study is to analysis feasibility to apply technology of generating dynamic password to the special authentication process on web-based service. Main concept of this study refers to the concept of token device, device based technology of generating one-time password, which has the crosscheck process with the server side application. Some applied sub processes in this approach refer to challenge-response system. Results revealed the possibility of applied processes to use one-time password instead constant password in the specific transaction of web-based service. Although the alternative authentication approach was related to the increasing conviction in beneficial transaction on public web-based service, the system still needed the constant password in case of authentication for beginning transaction. The complication of overall processes related to the confusion of users, who never knew about challenge-response concept, to understand the specific type of service. These findings suggest that there are some processes in this approach that have to be improved for more security. The alternative authentication by generating one-time password should be considered to improve the algorithm of encoding data in case of using by real public web service. In addition, there are many technologies that can be considered to apply to this alternative approach such as apply handheld device to be one-time password generator or using wireless equipment instead email channel to inform message to client users.