OTP-Based Two-Factor Authentication Using Mobile Phones

Mohamed Hamdy Eldefrawy,Khaled Alghathbar,Muhammad Khurram Khan
DOI: https://doi.org/10.1109/itng.2011.64
2011-04-01
Abstract:Two-factor authentication (2FA) provides improved protection, since users are prompted to provide something they know and something they have. This method delivers a higher level of authentication assurance, which is essential for online banking security. Many banking systems have satisfied the 2FA requirements by sending a One Time Password (OTP), something possessed, through an SMS to the user's phone device. Unfortunately, international roaming and SMS costs and delays put restrictions on this system reliability. This paper presents a novel two-factor authentication scheme whereby a user's device produces multiples OTPs from an initial seed using the proposed production scheme. The initial seed is produced by the communications partners' unique parameters. Applying the many from one function to a certain seed removes the requirement of sending SMS-based OTPs to users, and reduces the restrictions caused by the SMS system.
What problem does this paper attempt to address?