2 cissp ® Official Study Guide Eighth Edition


Synchronous Dynamic Password Tokens



Download 19,3 Mb.
Pdf ko'rish
bet555/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   551   552   553   554   555   556   557   558   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Synchronous Dynamic Password Tokens
Hardware tokens that create
synchronous 
dynamic passwords
are time-based and synchronized with an authentication server. They 
generate a new password periodically, such as every 60 seconds. This does require the token 
and the server to have accurate time. A common way this is used is by requiring the user to 
enter a username, a static password, and the dynamic onetime password into a web page. 
Asynchronous Dynamic Password Tokens
An
asynchronous dynamic password
does not 
use a clock. Instead, the hardware token generates passwords based on an algorithm and an 
incrementing counter. When using an incrementing counter, it creates a dynamic onetime 
password that stays the same until used for authentication. Some tokens create a onetime 
password when the user enters a PIN provided by the authentication server into the token. 
For example, a user would fi rst submit a username and password to a web page. After 


594
Chapter 13 

Managing Identity and Authentication
validating the user’s credentials, the authentication system uses the token’s identifier and 
incrementing counter to create a challenge number and sends it back to the user. The chal-
lenge number changes each time a user authenticates, so it is often called a nonce (short for 
“number used once”). The challenge number will only produce the correct onetime pass-
word on the device belonging to that user. The user enters the challenge number into the 
token and the token creates a password. The user then enters the password into the website 
to complete the authentication process.
Hardware tokens provide strong authentication, but they do have failings. If the battery 
dies or the device breaks, the user won’t be able to gain access.
Some organizations use the same concepts but provide the PIN via a software applica-
tion running on the user’s device. As an example, Symantec supports the VIP Access app. 
After it’s configured to work with an authentication server, it sends a new six-digit PIN to 
the app every 30 seconds.
onetime Password Generators
Onetime passwords are dynamic passwords that change every time they are used. They 
can be effective for security purposes, but most people find it difficult to remember pass-
words that change so frequently. Onetime password generators are token devices that 
create passwords, making onetime passwords reasonable to deploy. With token-device-
based authentication systems, an environment can benefit from the strength of onetime 
passwords without relying on users to be able to memorize complex passwords.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   551   552   553   554   555   556   557   558   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish