RFC 6238: TOTP: Time-Based One-Time Password Algorithm
In plain English — editorial summary, not part of the RFC
This document describes an extension of the One-Time Password (OTP) algorithm, namely the HMAC-based One-Time Password (HOTP) algorithm, as defined in RFC 4226, to support the time-based moving factor. The HOTP algorithm specifies an event-based OTP algorithm, where the moving factor is an event counter. The present work bases the moving factor on a time value. A time-based variant of the OTP algorithm provides short-lived OTP values, which are desirable for enhanced security. The proposed algorithm can be used across a wide range of network applications, from remote Virtual Private Network (VPN) access and Wi-Fi network logon to transaction-oriented Web applications. The authors believe that a common and shared algorithm will facilitate adoption of two-factor authentication on the Internet by enabling interoperability across commercial and open-source implementations. This document is not an Internet Standards Track specification; it is published for informational purposes.
Document record
- Document ID
- RFC6238
- Published
- May 2011
- Authors
- D. M'Raihi; S. Machani; M. Pei; J. Rydell
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- —
- Pages
- 16
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4226HOTP: An HMAC-Based One-Time Password AlgorithmCurrent
December 2005
- RFC 6287OCRA: OATH Challenge-Response AlgorithmCurrent
June 2011
- RFC 6030Portable Symmetric Key Container (PSKC)Current
October 2010
- RFC 4793The EAP Protected One-Time Password Protocol (EAP-POTP)Current
February 2007
- RFC 2289A One-Time Password SystemCurrent
February 1998
- RFC 1938A One-Time Password SystemObsoleted
May 1996
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?