Browse > Article
http://dx.doi.org/10.5762/KAIS.2013.14.3.1409

A Study on the Variable Password Generation Method in Internet Authentication System  

Kang, Jung-Ha (Dept. of Information and Communication Engineering, Hanbat National University)
Kim, Jae Young (IT Convergence Technology Research Lab., Electronics and Telecommunications Research Institute)
Kim, Eun-Gi (Dept. of Information and Communication Engineering, Hanbat National University)
Publication Information
Journal of the Korea Academia-Industrial cooperation Society / v.14, no.3, 2013 , pp. 1409-1415 More about this Journal
Abstract
With the development of Internet communication and the use of a variety of online services has been greatly expanded. Therefore, the importance of authentication techniques for users of online services has increased. The most commonly used methods for user authentication is a technique that utilizes a prearranged password. However, the existing password scheme for authentication must use the same password every time. Therefore, the password being leaked by attackers, it can be used maliciously. In this paper, we proposed the Variable Password Generation Method in Internet Authentication System that generates a new password using information such as the access date, time, and IP address when user logs in. The method proposed in this paper prevents disclosure of personal information due to password exposure and improves the reliability and competitiveness in the field of security systems.
Keywords
Authentication; Password; Security; Password Generation; Password Policy;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Karen Scarfone, Murugiah Souppaya,"Guide to Enterprise Password Management(Draft)", p.11-13, NIST, 2009.
2 Ant Allan, "A Taxonomy of Authentication Methods", p.10-30, Gertneer, 2011.
3 William E, Burr, Donna F. Dodson, Elaine M. Newton, Ray A. Perlner, W, "e-authentication guideline", p.19-38, NIST, 2011.
4 ITU-T, "Entity authentication assurance", p.9-15, ITU-T, 2011.
5 FFIEC "Supplement to Authentication in an Internet Banking Environment", p.1-7, FFIEC, 2011.
6 Neil M. Haller, "The S/Key One-Time Password System", p.1-5, RFC 1760, 1995.