SmartOTPs: An Air-Gapped 2-Factor Authentication for Smart-Contract Wallets
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26230%2F26%3A0191341" target="_blank" >RIV/00216305:26230/26:0191341 - isvavai.cz</a>
Výsledek na webu
<a href="https://github.com/ivan-homoliak-sutd/SmartOTPs?tab=readme-ov-file" target="_blank" >https://github.com/ivan-homoliak-sutd/SmartOTPs?tab=readme-ov-file</a>
DOI - Digital Object Identifier
—
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
SmartOTPs: An Air-Gapped 2-Factor Authentication for Smart-Contract Wallets
Popis výsledku v původním jazyce
We propose and develop SmartOTPs, a smart-contract wallet framework that gives a flexible, usable, and secure way of managing crypto-tokens in a self-sovereign fashion. The proposed framework consists of four components (i.e., an authenticator, a client, a hardware wallet, and a smart contract), and it provides 2-factor authentication (2FA) performed in two stages of interaction with the blockchain. To the best of our knowledge, our framework is the first one that utilizes one-time passwords (OTPs) in the setting of the public blockchain. In SmartOTPs, the OTPs are aggregated by a Merkle tree and hash chains whereby for each authentication only a short OTP (e.g., 16B-long) is transferred from the authenticator to the client. Such a novel setting enables us to make a fully air-gapped authenticator by utilizing small QR codes or a few mnemonic words, while additionally offering resilience against quantum cryptanalysis. We have made a proof-of-concept based on the Ethereum platform. Our cost analysis shows that the average cost of a transfer operation is comparable to existing 2FA solutions using smart contracts with multi-signatures.
Název v anglickém jazyce
SmartOTPs: An Air-Gapped 2-Factor Authentication for Smart-Contract Wallets
Popis výsledku anglicky
We propose and develop SmartOTPs, a smart-contract wallet framework that gives a flexible, usable, and secure way of managing crypto-tokens in a self-sovereign fashion. The proposed framework consists of four components (i.e., an authenticator, a client, a hardware wallet, and a smart contract), and it provides 2-factor authentication (2FA) performed in two stages of interaction with the blockchain. To the best of our knowledge, our framework is the first one that utilizes one-time passwords (OTPs) in the setting of the public blockchain. In SmartOTPs, the OTPs are aggregated by a Merkle tree and hash chains whereby for each authentication only a short OTP (e.g., 16B-long) is transferred from the authenticator to the client. Such a novel setting enables us to make a fully air-gapped authenticator by utilizing small QR codes or a few mnemonic words, while additionally offering resilience against quantum cryptanalysis. We have made a proof-of-concept based on the Ethereum platform. Our cost analysis shows that the average cost of a transfer operation is comparable to existing 2FA solutions using smart contracts with multi-signatures.
Klasifikace
Druh
G<sub>funk</sub> - Funkční vzorek
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
—
Návaznosti
I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Interní identifikační kód produktu
SmartOTPs
Číselná identifikace
9781450381390
Technické parametry
The parameters of the product are describe in our paper https://dl.acm.org/doi/abs/10.1145/3419614.3423257 We developed software implementation of smart contract wallet, client DAPP, and authenticator App (both as Android app as well as hardware implementation on ESP8266 MCU).
Ekonomické parametry
No known. The product is licensed under MIT license, and its altered version is used by Harmony One Wallet - https://github.com/polymorpher/one-wallet. At the peak times of Harmony, its OneWallet secured hundreds of millions of USD.
Kategorie aplik. výsledku dle nákladů
—
IČO vlastníka výsledku
00216305
Název vlastníka
Vysoké učení technické v Brně
Stát vlastníka
CZ - Česká republika
Druh možnosti využití
N - Využití výsledku jiným subjektem je možné bez nabytí licence (výsledek není licencován)
Požadavek na licenční poplatek
N - Poskytovatel licence na výsledek nepožaduje licenční poplatek
Adresa www stránky s výsledkem
https://github.com/ivan-homoliak-sutd/SmartOTPs?tab=readme-ov-file