skip to main content
10.1145/3424954.3424966acmotherconferencesArticle/Chapter ViewAbstractPublication PageseiccConference Proceedingsconference-collections
poster

Covert Channels in One-Time Passwords Based on Hash Chains

Published:12 January 2021Publication History

ABSTRACT

We present a covert channel between two network devices where one authenticates itself with Lamport's one-time passwords based on a cryptographic hash function. Our channel enables plausible deniability. We also present countermeasures to detect the presence of such a covert channel, which are non-trivial because hash values are randomly looking binary strings, so that deviations are not likely to be detected.

References

  1. C. Abad. 2001. IP Checksum Covert Channels and Selected Hash Collision. Technical Report. Univ. of California, Los Angeles.Google ScholarGoogle Scholar
  2. R. Anderson, R. Needham, and A. Shamir. 1998. The steganographic file system. In International Workshop on Information Hiding. Springer, 73--82.Google ScholarGoogle Scholar
  3. T. E. Calhoun Jr, X. Cao, et al. 2012. An 802.11 MAC layer covert channel. Wireless Communications and Mobile Computing 12, 5 (2012), 393--405.Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. S. Craver, E. Li, and J. Yu. 2009. Protocols for data hiding in pseudo-random state. In Media Forensics and Security, Vol. 7254.Google ScholarGoogle Scholar
  5. N. Haller. 1995. The S/KEY One-Time Password System. RFC 1760. RFC Editor. https://www.rfc-editor.org/rfc/rfc1760.txtGoogle ScholarGoogle Scholar
  6. L. Lamport. 1981. Password authentication with insecure communication. Commun. ACM 24, 11 (1981), 770--772. https://doi.org/10.1145/358790.358797Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. B. W. Lampson. 1973. A Note on the Confinement Problem. Commun. ACM 16, 10 (Oct. 1973), 613--615. https://doi.org/10.1145/362375.362389Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. A.J. Menezes, P. C. van Oorschot, and S. A. Vanstone. 1996. Handbook of Applied Cryptography. CRC Press.Google ScholarGoogle Scholar
  9. A. Perrig, R. Canetti, et al. 2002. The TESLA Broadcast Authentication Protocol. CryptoBytes 5, 2 (2002), 2--13.Google ScholarGoogle Scholar
  10. S. Wendzel, S. Zander, et al. 2015. Pattern-Based Survey and Categorization of Network Covert Channel Techniques. Computing Surveys 47, 3 (2015).Google ScholarGoogle Scholar

Index Terms

  1. Covert Channels in One-Time Passwords Based on Hash Chains

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Other conferences
          EICC '20: Proceedings of the 2020 European Interdisciplinary Cybersecurity Conference
          November 2020
          72 pages
          ISBN:9781450375993
          DOI:10.1145/3424954

          Copyright © 2020 Owner/Author

          Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 12 January 2021

          Check for updates

          Qualifiers

          • poster
          • Research
          • Refereed limited

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader