Anar al contingut

Google Authenticator

De L'Enciclopèdia, la wikipedia en valencià
Google Authenticator

Google Authenticator és un software basat en autenticació en contrasenya d'un sol us desenrollat per Google. Google Authenticator oferix un número de sis dígits que l'usuari deu proporcionar ademés del seu nom d'usuari i contrasenya per a accedir als servicis de Google. Google Authenticator pot també generar còdics per a aplicacions de terceres parts, tals com gestors de contrasenyes o servicis d'estage d'archius.

Implementacions

Google oferix versions de Google Authenticator per a Android,[1] BlackBerry i iOS.[2]

Existixen també vàries implementacions de terceres parts;

  • Windows Phone 7.5/8: Authenticator Virtual TokenFactor
  • Windows Mobile: Google Authenticator for Windows Mobile
  • Java CLI: Authenticator. jar
  • Java GUI: JAuth
  • J2EM: gauthj2em lwuitgauthj2em Mobile-OTP (chinese only) totp-em * PAMS:

gauthj2em * Python: onetimepass

  • PHP: GoogleAuthenticator. php
  • Ruby: google_authenticator_auth gem (third party implementation)
  • Rails: active_model_otp (third party implementation)
  • webOS: GAuth
  • Windows: gauth4win MOS Authenticator
  • . NET: TwoStepsAuthenticator
  • HTML5: html5-google-authenticator
  • MeeGo/Harmattan (Nokia N9): GAuth
  • Apache: Google Authenticator Apache Module
  • PAM: Google Pluggable Authentication Module oauth-pam
  • @Web Browser Online : Yashvasin Authenticator

Descripció tècnica

Google Authenticator inclou implementacions per a la generació de còdics d'autenticació en contrasenya d'un sol us destinat a vàries plataformes mòvils, aixina com un mòdul d'autenticació (PAM) conectable. Els còdics One-clave són generats fent us d'estàndarts oberts desenrollats per The Initiative for Open Authentication (OATH) (no guarda relació en OAuth).

Estes implementacions soporten l'algoritme HMAC-Based One-clave Password (HOTP) especificat en la RFC 4226 i l'algoritme Clave-based One-clave Password (TOTP) especificat en la RFC 6238.

El proveïdor de servici genera una clau secreta de 80 bits per a cada usuari. Esta se suministra com una cadena de 16 caràcters codificats en base32 o com un QR code. El client crea un mensage HMAC-SHA1 usant esta clau secreta. El mensage aixina generat pot estar basat en;

  • El número de periodos de 30 segons transcorreguts des d'Unix epoch; o
  • El contador que és incrementat en cada nou còdic.

Una porció de la HMAC s'extrau i és convertida a un còdic de 6 dígits.

Pseudo còdic per a Clave OTP

 function GoogleAuthenticatorCode(string secret)
     key := base32decode(secret)
     message := current Unix clave ÷ 30#:= HMAC-SHA1(key, message)
     offset := last nibble of#truncated#:=#[offset.. offset+3]  //4 bytes starting at the offset
     Set the first bit of truncated#to zero  //remove the most significant bit 
     code := truncated#mod 1000000
     pad code with 0 until length of code is 6
     return code 

Pseudo còdic per a Event/Counter OTP

Referències