Skip to main content

Submit an Internet-Draft

Submission status: Posted

Submission checks

Your Internet-Draft has been verified to pass the submission checks.

Meta-data from the submission

Document draft-strbac-totp2
Revision 00
Group Individual Submission
Document date 2023-07-23
Submission date 2023-07-23
Title TOTP2 Authentication Scheme
Author count 1 author
Author 1 Dejan Strbac <dejan@mercata.com>
Mercata SagL
Switzerland
Abstract We present a second-factor authentication scheme that extends the
Time-Based One-Time Password (TOTP) method to provide superior
protection against phishing attacks.

Unlike traditional one-time password flows that solely authenticate
the user with the service, our approach introduces an extended flow
that seamlessly authenticates both the user and the service to each
other. This enhanced process ensures a secure submission of the
user's second-factor authentication via a secondary and secure
communication channel.

By verifying the service's authenticity to the user, our scheme
establishes a robust defence against potential phishing attempts,
enhancing the overall security of the authentication process.
Page count 12
File size 25.3 KB
Formal languages used ABNF
Submission additional resources None

Submitter information

Name Dejan Strbac
Email address dejan@mercata.com

History

Date By Event
2023-07-23 Confirmed and posted submission
2023-07-23 Set submitter to "Dejan Strbac <dejan@mercata.com>", replaces to (none) and sent confirmation email to submitter and authors: Dejan Strbac <dejan@mercata.com>
2023-07-23 Completed submission validation checks
2023-07-23 Uploaded submission
Please send reports about submission tool bugs to the Tools Team using one of the Bug Report links at the bottom of the page.
If you run into problems submitting an Internet-Draft and need to request manual posting of an Internet-Draft, please send the Internet-Draft and the reason for manual posting to support@ietf.org. Be advised that manual processing always takes additional time.