As my first post in this new blog I want to make something a little bit "different". For this reason, this post is about "one time password" (OTP) generation mixed with a little bit of Model View Controller (MVC). The idea for this post is to make an overview (with a little bit of code, of course!) over an authenticator that Google uses.
Most of you already would know about OTP, but if not, your are in the right place. A one-time password (OTP) is a password that is valid for only one login session or transaction. OTPs avoid a number of shortcomings that are associated with traditional (static) passwords. The most important shortcoming that is addressed by OTPs is that, in contrast to static passwords, they are not vulnerable to replay attacks. This means that a potential intruder who manages to record an OTP that was already used to log into a service or to conduct a transaction will not be able to abuse it, since it will be no longer valid. On the downside, OTPs are difficult for human beings to memorize. Therefore they require additional technology to work.
My application is basically a login form which uses username and an OTP provided by the server to login users. The OTP last 30 seconds, after this time, it will expire and the user will need to generate a new one. Now I am going to explain the different parts of my code to make easier your comprehension. First I start with a screenshot of the different program parts and the arquitecture:
- Controllers: Encryption.cs is the engine of the app and who generates the OTP password from the user id and a random number. LoginController.cs is the second most important part and is dedicated on handle the user inputs and the management of the information between the Login view and the model.
- Models: just User.cs class is needed to handle the user information (login, otp, otp creation date, logged)
- Views: UserGetOtp.aspx is the first view where the user writes his login name; UserLogin.aspx is shown to finish the login process with the OTP provided. Finally, after a succesful log process, the Account.aspx view, from the Private Area is shown.
Here bellow you can see the core of the application, the OTP generation method. This algorithm is explained in the point 5.4 of the RFC4226 (see references at the bottom):
