RFC 4226: HOTP: An HMAC-Based One-Time Password Algorithm
In plain English — editorial summary, not part of the RFC
This document describes an algorithm to generate one-time password values, based on Hashed Message Authentication Code (HMAC). A security analysis of the algorithm is presented, and important parameters related to the secure deployment of the algorithm are discussed. The proposed algorithm can be used across a wide range of network applications ranging from remote Virtual Private Network (VPN) access, Wi-Fi network logon to transaction-oriented Web applications. This work is a joint effort by the OATH (Open AuTHentication) membership to specify an algorithm that can be freely distributed to the technical community. The authors believe that a common and shared algorithm will facilitate adoption of two-factor authentication on the Internet by enabling interoperability across commercial and open-source implementations. This memo provides information for the Internet community.
Document record
- Document ID
- RFC4226
- Published
- December 2005
- Authors
- D. M'Raihi; M. Bellare; F. Hoornaert; D. Naccache; O. Ranen
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- —
- Pages
- 37
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4217Securing FTP with TLSUpdated
October 2005
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
- RFC 4302IP Authentication HeaderCurrent
December 2005
- RFC 4303IP Encapsulating Security Payload (ESP)Current
December 2005
- RFC 4305Cryptographic Algorithm Implementation Requirements for Encapsulating Security Payload (ESP) and Authentication Header (AH)Obsoleted
December 2005
- RFC 4306Internet Key Exchange (IKEv2) ProtocolObsoleted
December 2005
- RFC 4109Algorithms for Internet Key Exchange version 1 (IKEv1)Current
May 2005
- RFC 4366Transport Layer Security (TLS) ExtensionsObsoleted
April 2006
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?