> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/notes-mcs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/notes-mcs/identification-authentication-and-authorization/authentication-protocols/authentication-of-people/token-based-otp-generators.md).

# Token-based OTP generators

## RSA SecurID

Personal authentication token.

* Or software modules for handhelds (PDAs, smartphones, etc.).

**It generates a unique number at a fixed rate.**

* Usually one per minute (or 30 seconds).
* Bound to a person (User ID)
* A unique number computed with:
  * A 64-bit key is stored in the token.
  * The actual timestamp.
  * A proprietary digest algorithm (SecurID hash).
  * An extra PIN (only for some tokens)

**OTP-based authentication.**

* A user **combines their User ID with the current token number**.
  * OTP = User ID, Token Number.

An RSA ACE Server does the same and checks for a match.

* It also knows the person’s key stored in the token.
* There must be a synchronization to tackle clock drifts.
  * RSA Security Time Synchronization.

**Robust against dictionary attacks** since keys are not selected by people.

## Yubikey

**Personal Authentication Device**

* USB and/or NFC.

Activation **generates a 44-character key**.

* Emulates a USB keyboard (besides its API).
* Supports HOTP (events) or TOPT (Temporal).
* If a challenge is provided, the user must touch the button to obtain a result.
* Several algorithms, including AES 256.

<figure><img src="https://3490214077-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAHT7avzIVwxfPJ4pkhhO%2Fuploads%2FgxvRwZpJ3iFU7QLKrhuO%2Fimage.png?alt=media&amp;token=f30faccc-591c-4233-93de-efc1ea8f9242" alt=""><figcaption></figcaption></figure>
