研究生: 方俊斌
Chun-pin Fang
論文名稱: 基於一次性動態密碼及行動裝置進行身分驗證
A New Identity Authentication System Based On OTP Using Mobile Device
指導教授: 洪西進
Shi-Jinn Horng
口試委員: 古鴻炎
Hung-yan Gu
Hung-Hsu Tsai
Ji-Han Jiang
學位類別: 碩士
系所名稱: 電資學院 - 資訊工程系
Department of Computer Science and Information Engineering
論文出版年: 2012
畢業學年度: 100
語文別: 中文
論文頁數: 57
中文關鍵詞: 一次性動態密碼身分驗證Challenge/ResponseRSA演算法
外文關鍵詞: One Time Password, Identity Authentication, Challenge/Response, RSA Algorithm
  • 隨著電子商務[1]快速成長,電子商務(如線上銀行、購物、交易)最常要求使用者輸入帳號(Username)與密碼(Password)來登入系統,進行身分驗證。由於每位使用者可能同時使用多個電子商務系統,所以,要記憶多組帳號與密碼極有可能造成他們的困擾。另外,在這開放的網路世界,合法使用者的帳號與密碼遭有心人士盜取使用的新聞時有所聞。再則,近年來電子商務系統常使用透過簡訊來傳送一次性動態密碼[2] OTP (One Time Password),來保護使用者的身分驗證。使用者收到簡訊後,再次輸入其OTP,才能登入系統。

    With the fast growth of e-commerce [1] systems, more and more people rely on them to finish their tasks, such as using an online banking, shopping, or trading. The users of the systems are usually required to type in their username and password to log into the system to verify their identity. However, these users may find it difficult to memorize all of the usernames and passwords for different systems if a number of systems are used. In addition, it is often heard that a user’s username and password for a system are phished in cyberspace. Therefore, in order to protect users’ authentication, e-commerce systems now more frequently send a one time password (OTP) through a text to their users. The users can use their OTP they receive to log onto the e-commerce system.
    Many e-commerce users are used to carrying a mobile device with them. The thesis will mainly discuss the convenience and advantages of using a mobile device to log into a system with an OTP. Users use an OTP generator in their mobile device to gain an OTP. This OTP can be used just once. By using the OTP to log onto an e-commerce system, users may not confuse their usernames and passwords for different websites as well as ensure their safety when logging into systems.

    中文摘要 III Abstract IV 致謝 V 目錄 VI 表目錄 IX 圖目錄 X 第一章 導論 1 1.1 研究背景與動機 1 1.2 貢獻 2 第二章 相關工作 4 2.1 一次性動態密碼 (One Time Password) 4 2.1.1 硬體式OTP 載具(Token) 6 2.1.2 簡訊OTP 6 2.1.3 查表式OTP 7 2.1.4 軟體式行動裝置OTP 8 2.2 現今網路身分驗證的機制 9 2.2.1 帳號與密碼 9 2.2.2 IP鎖 10 2.2.3 電腦憑證 10 2.2.4 OTP動態密碼鎖 11 2.2.5 防盜密碼信用卡 12 2.2.6 簡訊安全鎖 12 2.2.7 電話鎖 13 2.2.8 IC晶片卡 13 2.2.9 雙重/多重因素認證 14 第三章 動態密碼與密碼演算法之技術研究 16 3.1 密碼學演算法 16 3.2 對稱性密碼 18 3.3 非對稱性密碼 19 3.4 混合型密碼 21 3.5 亂數 22 第四章 系統架構及安全效能分析 24 4.1 One Time Password Via SMS系統架構 24 4.2 系統運作架構 26 4.3 系統架構之流程機制 28 4.4 實作成果 33 4.4.1 實作環境 33 4.4.2 實作步驟說明 34 4.5 系統安全效能分析 39 4.5.1 安全評估分析 39 4.5.2 優缺點分析 40 4.5.3 效能評估分析 40 第五章 結論及未來展望 41 5.1 結論 41 5.2 未來展望 41 參考文獻 43

