Password you don't need to remember! BaroOTP is with you.
BaroOTP solution is a software method (soft OTP, 2nd OTP) authentication solution that creates a One Time Password on a smart phone (Android, iPhone).
1. Strong authentication solution
1) In order to receive user authentication, a new OTP must be used every time. It is volatile and can only be used once, and it is safe even when ID/PW is leaked.
2) OTP once used cannot be reused, and it is difficult to infer a number, providing strong security against various hacking attacks.
2. Ease of service
1) Authentication processing using the smartphone of the user who normally carries it without carrying a separate OTP device.
2) Password is unnecessary because login processing is possible only with ID and authentication key for each user of the information system.
3. Cost reduction
1) Reduced management/operation costs with a structure that does not require a separate authentication server
2) Reduced hardware OTP purchase cost
Hacking damage for corporate and personal information leakage (online banking accident, email hacking, website hacking, server hacking, card information exposure, account information exposure, identity theft, company/personal information leakage) reports continue to occur as long as they are forgotten. And the damage to it is serious. More fundamentally, there is a growing social awareness that it is necessary to respond to hacking by using a safe one-time password.
1. Use of guessable password (anniversary, phone number)
2. Unification with one or two IDs/PWs that are easy to remember in most cases
3. Difficulty for users to determine whether or not it is leaked in the event of a leak
4. My computer is always exposed to viruses or hacking
5. Inconvenient to use because of too many passwords
Passwords are never secure, and you need a one-time password that can be replaced each time you use it.
BaroOTP is a 2nd generation TOTP (Time-based One Time Password), which creates and authenticates a one-time password with an OTP generation module (soft OTP) in a smart phone (Android, iPhone) instead of an OTP device. It is the optimal solution for preventing account theft and controlling access to the system.
1.Use of 512bit standard hash function (HMAC-SHA512) recognized worldwide (Internet security standard IETF RFC 6238)
2. Time-Sync method recommended by Financial Supervisory Service and dynamic SEED encryption algorithm composition
3. Can be used in all fields requiring user authentication, such as electronic financial transactions, online services, e-commerce, and server access control.
4. Software method that does not require a separate authentication server (2nd OTP)
5. Authentication key and OTP generation cycle (3~60 seconds) individually assigned for each server and account
6. Supports password substitution for 2-factor/2-channel authentication
7. Unlike hardware OTP, it can be permanently used as soft OTP.
8. Free customization and convenience of interlocking development with various application programs (Java, C language API interworking)
※ HMAC (Hash-based Message Authentication Code): Hash-based message authentication code
HMAC is a method of combining keys to obtain a hash function, and a method of creating a hash value by mixing a key and a message shared only by the sender and the receiver. In addition, it can be used to check whether a message sent through a channel is damaged, and since inverse calculation is impossible due to MAC characteristics, it is a method of recalculating the received message and the hash value to check whether the calculated HMAC and the transmitted HMAC match.
Inquiries: mc529@nurit.co.kr