Network Working Group N. Haller
Request for Comments: 1760 Bellcore
Category: Informational February 1995
The S/KEY One-Time Password System
Haller [Page 1]
RFC 1760 The S/KEY One-Time Password System February 1995
Introduction
Haller [Page 2]
RFC 1760 The S/KEY One-Time Password System February 1995
The client's secret pass phrase may be of any length and should be more than eight characters. As the S/KEY secure hash function described above accepts a 64 bit input, a preparatory step is needed. In this step, the pass phrase is concatenated with a seed that is transmitted from the server in clear text. This non-secret seed allows a client to use the same secret pass phrase on multiple machines (using different seeds) and to safely recycle secret passwords by changing the seed. (For ease in parsing, the seed may not contain any blanks, and should consist of strictly alphanumeric characters.) The result of the concatenation is passed through MD4, and then reduced to 64 bits by exclusive-OR of the two 8-byte halves.
Haller [Page 3]
RFC 1760 The S/KEY One-Time Password System February 1995
Verification of One-Time Passwords
Haller [Page 4]
RFC 1760 The S/KEY One-Time Password System February 1995
key [-n count] sequence seed
Haller [Page 5]
RFC 1760 The S/KEY One-Time Password System February 1995
Security Considerations
Haller [Page 6]
RFC 1760 The S/KEY One-Time Password System February 1995
Dictionary for Converting Between S/KEY 6-Word and Binary Formats
Haller [Page 7]
RFC 1760 The S/KEY One-Time Password System February 1995 Haller [Page 8]
RFC 1760 The S/KEY One-Time Password System February 1995 Haller [Page 9]
RFC 1760 The S/KEY One-Time Password System February 1995 Haller [Page 10]
RFC 1760 The S/KEY One-Time Password System February 1995 Haller [Page 11]
RFC 1760 The S/KEY One-Time Password System February 1995
Haller [Page 12]