Re: [PHP3] S/Key implementation using PHP?
| From: | (Richard Lynch) | Date: | Fri, 09 Jun 2000 19:46:52 +0000 |
| Subject: | Re: [PHP3] S/Key implementation using PHP? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1421@lists.php.net to get a copy of this message | ||
In article <EKEOKBELHPBMNHPHMOPDMEDCDBAA.roy@vem.ca>, roy@vem.ca ("Roy
Nasser") wrote:
> I downloaded a program for my Palm that generates an S/Key "key" (I guess
> thats what its called), based on a seed, a count, and a password. I was
> wondering if it would be possible to create the "server" system for this
> kind of "client" authentication...?
You'd have to find out what the under-lying key generation routine is
called... What you describe could be any of a large number of solutions,
I think...
Unless S/Key is just one I ain't heard of, which is quite likely...
> Basically, i would have a PHP script that asked the user to login with his
> Key, and have the seed and the count there (these values could change
> throughtout the day?).
>
> This would be secure because the password is known only by the server and
> the user, not the network (i.e. he does not transmit his password), so one
> piece of the puzzle is never transmitted in clear-text...
>
> What other types of security has been implemented?
Woof. That's a pretty long list...
RSA
DES
Blowfish
Twofish
.
.
.
They all have different strenghts and weaknesses and can be classified
into several broad categories.
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)