<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">OJAppS</journal-id><journal-title-group><journal-title>Open Journal of Applied Sciences</journal-title></journal-title-group><issn pub-type="epub">2165-3917</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/ojapps.2016.613077</article-id><article-id pub-id-type="publisher-id">OJAppS-73043</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Biomedical&amp;Life Sciences</subject><subject> Chemistry&amp;Materials Science</subject><subject> Computer Science&amp;Communications</subject><subject> Engineering</subject><subject> Physics&amp;Mathematics</subject></subj-group></article-categories><title-group><article-title>
 
 
  Research and Implementation of Time Synchronous Dynamic Password Based on SM3 Hash Algorithm
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Dognery</surname><given-names>Sinaly Silue</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Wanggen</surname><given-names>Wan</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Muhammad</surname><given-names>Rizwan</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib></contrib-group><aff id="aff2"><addr-line>Institute of Smart City, Shanghai, China</addr-line></aff><aff id="aff1"><addr-line>School of Communications and Information Engineering, Shanghai University, Shanghai, China</addr-line></aff><pub-date pub-type="epub"><day>06</day><month>12</month><year>2016</year></pub-date><volume>06</volume><issue>13</issue><fpage>893</fpage><lpage>902</lpage><history><date date-type="received"><day>November</day>	<month>13,</month>	<year>2016</year></date><date date-type="rev-recd"><day>Accepted:</day>	<month>December</month>	<year>25,</year>	</date><date date-type="accepted"><day>December</day>	<month>28,</month>	<year>2016</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  With the rapid development of information technology, demand of network &amp; information security has increased. People enjoy many benefits by virtue of information technology. At the same time network security has become the important challenge, but network information security has become a top priority. In the field of authentication, dynamic password technology has gained users’ trust and favor because of its safety and ease of operation. Dynamic password, SHA (Secure Hash Algorithm) is widely used globally and acts as information security mechanism against potential threat. The cryptographic algorithm is an open research area, and development of these state-owned technology products helps secure encryption product and provides safeguard against threats. Dynamic password authentication technology is based on time synchronization, using the state-owned password algorithm. SM3 hash algorithm can meet the security needs of a variety of cryptographic applications for commercial cryptographic applications and verification of digital signatures, generation and verification of message authentication code. Dynamic password basically generates an unpredictable random numbers based on a combination of specialized algorithms. Each password can only be used once, and help provide high safety. Therefore, the dynamic password technology for network information security issues is of great significance. In our proposed algorithm, dynamic password is generated by SM3 Hash Algorithm using current time and the identity ID and it varies with time and changes randomly. Coupled with the SM3 hash algorithm security, dynamic password security properties can be further improved, thus it effectively improves network authentication security.
 
</p></abstract><kwd-group><kwd>Dynamic Password Authentication</kwd><kwd> SM3 Hash Algorithm</kwd><kwd> Network Authentication Security</kwd><kwd> One Time Password</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Internet and mobile communications have developed rapidly; it increases the demand for securing user authentications in terms of managing money and personal information [<xref ref-type="bibr" rid="scirp.73043-ref1">1</xref>] . However, there is always a risk of monitoring the personal &amp; private data. Therefore, it is necessary to authenticate users securely. If a user sends the same password for every session, an attacker can masquerade as the user and the attacker can get user’s password via the Internet. One-time password authentication methods use one- way functions extensively [<xref ref-type="bibr" rid="scirp.73043-ref2">2</xref>] . Moreover, a synchronous data communication procedure is possible for one-time password authentication methods and realizes mutual authentication using a one-time password method. So, the user requires one-time password authentication methods that change the verifier every time. When a user logs in to the system, the user sends masking data to the server and the server certifies the user using those masking data and the stored verifier. Then the user and the server use a one-time password authentication method and apply a one-way function. The security of dynamic password system is mainly dependent on the encryption algorithm. Nowadays, most of the dynamic password technology in the domestic market adopts foreign algorithms, such as RSA, SHA-1, MD4, MD5 and so on [<xref ref-type="bibr" rid="scirp.73043-ref3">3</xref>] . With the growth of such algorithms, probability of cracking these algorithms also increases by time. In 2005 professor Xiaoyun Wang of Shandong University, proposed the cracking strategy of two classic hash algorithm systems (MD5 and SHA-1), so that the collision to crack the hash algorithm has become possible [<xref ref-type="bibr" rid="scirp.73043-ref4">4</xref>] . It has improved construction of signature schemes with forward security in the random oracle model [<xref ref-type="bibr" rid="scirp.73043-ref5">5</xref>] . This shows that in the field of identity authentication, the use of open source algorithms creates more risk of security. For the use of encryption products, No. 273 order of the State Council of China has published the regulation of the administration of commercial cipher, which shows that country attaches great importance to the information security of the localization. In this paper, the design and implementation of a dynamic password technology based on national commercial encryption standard, are proposed to solve the problem as follows: adopting the national commercial encryption SM3 hash algorithm as an encryption algorithm, to achieve the dynamic password authentication and encryption algorithm of domestic design; proposing the time truncated password algorithm based on the time to improve the safety performance of the algorithm [<xref ref-type="bibr" rid="scirp.73043-ref6">6</xref>] .</p></sec><sec id="s2"><title>2. Related Technology</title><sec id="s2_1"><title>2.1. The Definition of Hash Function</title><p>Hash function maps arbitrary length input message for fixed length output value, and the fixed length output value is called the input message’s hash value. The definition of the hash function can be expressed as: <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x2.png" xlink:type="simple"/></inline-formula>is a set of bits that represent arbitrary length; <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x3.png" xlink:type="simple"/></inline-formula>is a set of bit strings that represent the length of n. In order to ensure the safety of the hash function, hash length n should be at least 256 bit. Usually there is the key in operation; the hash function is divided into two parts: hash function with key and hash function without key [<xref ref-type="bibr" rid="scirp.73043-ref7">7</xref>] . It is shows as follows.</p><sec id="s2_1_1"><title>2.1.1. Hash Function with Key</title><p>Hash function with hash key keeps the key participation in the process of operation. This kind of hash functions is required to satisfy all the security requirements and the hash value depends on the key input message, and key can calculate the corresponding hash value. It not only provides a complete test as well as provides the function for identity authentication, named as message authentication code (MAC). The nature of message and authentication code ensures the generation of right message with hash function [<xref ref-type="bibr" rid="scirp.73043-ref8">8</xref>] .</p></sec><sec id="s2_1_2"><title>2.1.2. Hash Function without Key</title><p>As compared to hash function with key, no key is used by hash function for the input messages, so this type of hash function does not have the function of identity authentication. It provides only integrity checking, such as tampering detection code (MDC). According to the properties of the MDC, it can be divided into weak one-way hash function (OWHF) and strong one-way hash function (CRHF) [<xref ref-type="bibr" rid="scirp.73043-ref9">9</xref>] .</p></sec></sec><sec id="s2_2"><title>2.2. SM3 Hash Algorithm Decryption</title><p>The SM3 hash function compresses any message no more than 2<sup>64</sup>-1 bits into a 256-bit hash value. The algorithm first pads any given message into n 512-bit message blocks. The hash function consists of the following two parts: the message expansion and the state update transformation.</p><p>Message Expansion: The message expansion of SM3 splits the 512-bit message blocks M into 16 words<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x4.png" xlink:type="simple"/></inline-formula>, and expands them into 68 expanded message words <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x5.png" xlink:type="simple"/></inline-formula> and 64 expanded message words <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x6.png" xlink:type="simple"/></inline-formula> as follows:</p><disp-formula id="scirp.73043-formula220"><graphic  xlink:href="http://html.scirp.org/file/4-2310683x7.png"  xlink:type="simple"/></disp-formula><p>State Update Transformation: The state update transformation starts from an initial value (A<sub>0</sub>, B<sub>0</sub>, C<sub>0</sub>, D<sub>0</sub>, E<sub>0</sub>, F<sub>0</sub>, G<sub>0</sub>, H<sub>0</sub>) = IV of eight 32-bit words and updates them in 64 steps. In step <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x8.png" xlink:type="simple"/></inline-formula> the 32-bit words <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x9.png" xlink:type="simple"/></inline-formula> and <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x10.png" xlink:type="simple"/></inline-formula> are used to update the state variables A<sub>i</sub>, B<sub>i</sub>, C<sub>i</sub>, D<sub>i</sub>, E<sub>i</sub>, F<sub>i</sub>, G<sub>i</sub>, H<sub>i</sub> as follows:</p><disp-formula id="scirp.73043-formula221"><graphic  xlink:href="http://html.scirp.org/file/4-2310683x11.png"  xlink:type="simple"/></disp-formula><p>where <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x12.png" xlink:type="simple"/></inline-formula></p><p>The bitwise Boolean functions <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x13.png" xlink:type="simple"/></inline-formula> and <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x14.png" xlink:type="simple"/></inline-formula> are defined as follows.</p><disp-formula id="scirp.73043-formula222"><graphic  xlink:href="http://html.scirp.org/file/4-2310683x15.png"  xlink:type="simple"/></disp-formula><disp-formula id="scirp.73043-formula223"><graphic  xlink:href="http://html.scirp.org/file/4-2310683x16.png"  xlink:type="simple"/></disp-formula><p>If M is the last block, then</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x17.png" xlink:type="simple"/></inline-formula>is the hash value. Otherwise it is part of the input of the next message block.</p></sec><sec id="s2_3"><title>2.3. Dynamic Password Generation Algorithm Based on SM3</title><p>Dynamic password, also known as a one-time password, which is a one-time e form of a password that changes by time, for user new password is created every time [<xref ref-type="bibr" rid="scirp.73043-ref10">10</xref>] [<xref ref-type="bibr" rid="scirp.73043-ref11">11</xref>] . In a certain time interval, a password can only be used once; repeated use of the same password will be rejected. The main idea of dynamic password is to add some uncertain factors in the process, such as the use of time, frequency of use or random numbers, and these changing factors acts as a dynamic factor of password. The basic goal is to improve the safety of password. Dynamic password technology has many advantages: randomness, dynamic, one-time. The current paper proposed SH3 based algorithm for dynamic password authentication generation based on time [<xref ref-type="bibr" rid="scirp.73043-ref12">12</xref>] . The dynamic password authentication scheme is time saver and used for dynamic token holding, keep synchronization based on time may be considered as dynamic token of the uncertain factors, the mutual authentication using same responsible for the algorithm to generate a consistent user login password. Only legitimate users can hold the token, the token time refreshed after 60 seconds, and creates new token after 60 seconds.</p><p>In addition, the time certification system and dynamic password authentication technology is based on, challenge/response mechanism of dynamic password authentication technology and the password sequence of dynamic password authentication technology. This certification system can therefore be explained as follows:</p><p>The basic idea of the technology authentication word dynamic password is, to create variable counter value as an uncertain factor and it has no relation with the principle of system time [<xref ref-type="bibr" rid="scirp.73043-ref13">13</xref>] . Therefore, the problem of time synchronization and certification has less communication between the two sides. Challenge and response of dynamic password identity authentication technology are based on the basic idea that the system certification randomly generates a number of challenges to the user. The users generate dynamic password according to the random number and their authentication information.</p><p>Proposed method has no strict synchronization requirements, so it can fundamentally avoid the problem of loss of step. But it needs to verify the operational steps, only one-way communication; several typical one-time password authentication mechanism [<xref ref-type="bibr" rid="scirp.73043-ref14">14</xref>] based on the time mechanism is relatively simple, and the client computation is small and has no special hardware requirements, and the anti-attack ability is strong.</p><p>The generation of dynamic password [<xref ref-type="bibr" rid="scirp.73043-ref15">15</xref>] is determined by three things; the sequence number “SN”, the key and time “T”. Sequence number “SN” and key are fixed but time “T” is changed in minutes, so the three factors constitute the text “M” as a variable, that is, the encrypted text is dynamic, so that it can prevent the attack [<xref ref-type="bibr" rid="scirp.73043-ref16">16</xref>] . At this point one-way hash function of the encryption algorithm, first encrypt the plaintext block. Our proposed SM3 algorithm is based on encryption algorithm for the state password, the plaintext string processing length is 256 bits (32 bytes, which accounted for 6 of T bytes of SN 6 bytes of key, 20 bytes). The design obviates the calculation steps of grouping plaintext, realize simple and feasible encryption algorithm.</p><p>The serial number “SN”, key and time “T” are connected to get the plain text string “M”. Time accurate to minutes, the format is “yyyymmddhhmm”. For example, t is assumed that the current time is 14:41 in February 27, 2012, that is, T = 201202271441, SN = 555888, key = 1122333344556677889900555888112233445566.</p><p>That is, M = 555888 778899001122334455 667788990020120022 144144556677889- 9001122. The overall goal of the above process is to get the initial password, so that it is difficult to guess.</p><p>It needs to convert 64-bit hexadecimal number to 6-bitdecimal number to produce the output hash value using SH3 Algorithm [<xref ref-type="bibr" rid="scirp.73043-ref17">17</xref>] .</p><p>The truncated dynamic password algorithm based on time and the implementation flow in <xref ref-type="fig" rid="fig1">Figure 1</xref>:</p><p>1) User ID, key, and time T after SM3 algorithm generates the hexadecimal array M [<xref ref-type="bibr" rid="scirp.73043-ref64">64</xref>];</p><p>2) Take T minute position t, m = t mod 10, remove the M [t], M [t + 10], M [t + 20], M [t + 30], M [t + 40], M [t +50] composition OTP [<xref ref-type="bibr" rid="scirp.73043-ref5">5</xref>] (hex);</p><p>3) The OTP [<xref ref-type="bibr" rid="scirp.73043-ref6">6</xref>] is converted to decimal, and combined into a decimal OTP’;</p><p>4) result 1 = OTP’ mod<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x18.png" xlink:type="simple"/></inline-formula>, is the final dynamic password generated by the dynamic password token based on SM3 algorithm.</p><p>For example, if the current time is 14:53, t = 53 mod 10 = 3 and this time recorded</p><fig id="fig1"  position="float"><label><xref ref-type="fig" rid="fig1">Figure 1</xref></label><caption><title> Dynamic password algorithm flowchart</title></caption><graphic mimetype="image"   position="float"  xlink:type="simple"  xlink:href="http://html.scirp.org/file/4-2310683x19.png"/></fig><p>for T [<xref ref-type="bibr" rid="scirp.73043-ref3">3</xref>] , plaintext encrypted, the output value M = debe9ff9 2275b8a1 38604889 c18e5a4d 6fdb70e5 387e5765 293dcba3 9c0c5732,to M [<xref ref-type="bibr" rid="scirp.73043-ref3">3</xref>] = f9, M [<xref ref-type="bibr" rid="scirp.73043-ref13">13</xref>] = 8e, M [<xref ref-type="bibr" rid="scirp.73043-ref23">23</xref>] = 65, order groups into OTP = f98e65, converted to decimal OTP’ = 16354917 and eventually generated dynamic password P = 16354917 mod <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/4-2310683x20.png" xlink:type="simple"/></inline-formula> = 354917. This method ensures the second dynamic of the password, which makes it impossible for the illegal users to obtain the key by guessing, and further improve the security of the dynamic password algorithm.</p></sec></sec><sec id="s3"><title>3. Implementation of Security Analysis</title><sec id="s3_1"><title>3.1. Challenge/Response and Time Synchronization Authentication Methods</title><p>Dynamic password authentication method is based on challenge/response and time synchronization mode and acts as dynamic authentication method, it has dynamic factor: challenge/response, generate random number by triggering event (such as login) produced Challenge code; it is a way to change the time synchronization time. When challenge/response user for login authentication system generates a random number-the challenge code is sent to the user. The code received by the user in an encryption algorithm which is mixed with the users own password and a random number is sent subsequently to the server, authentication system can authenticate users with the appropriate method for checking.</p><p>A time synchronization authentication method is the elapsed time of a factor of change, after hashing we make comparison between the current values of time together with the seed key. Time synchronization is actually a way of parallel computing authentication methods; regular time factor is utilized instead of the random challenge code, thereby reducing the authenticator with the inter-working certified party, simple, easy to use and so on. However, the boundaries of time synchronization authentication method for time synchronization and time accuracy are higher; In order to meet the requirements of time synchronization, time synchronization mode password over time is constant, the delay suffered or replay attacks, and since the time factor is a regular change, increasing the probability of attacks; achieving time synchronization server the challenge is more complex than the response server, usually combined with adaptive calibration mechanism (such as a server implementation of some design time window automatically adjust the design); the reliability of authentication is not as challenge- response type authentication method, the jumping point critical time will have a blind spot. In summary, the dynamic password authentication system improves the authentication mechanism and provides more security against threats; provide more emphasis on safety and reliability and use the challenge-response based authentication methodology [<xref ref-type="bibr" rid="scirp.73043-ref18">18</xref>] .</p></sec><sec id="s3_2"><title>3.2. Encryption/Decryption Mode and Parallel Computation Mode</title><p>Challenge/Response authentication can be implemented in two modes; encryption/de- cryption mode and parallel computation mode. Encryption/decryption mode authentication can be divided into public key system which is based on symmetric key system. On the other hand, randomized user authentication uses its private or shared symmetric key of the authentication server (AS) emitted RN encrypted challenge code, Then the encrypted authentication result respond back to the server, using the corresponding public key or shared symmetric key to decrypt the response code, as a result if same RN is generated then the user authentication is successful. In the encryption/decryption of authentication mode, the speed is relatively slow due to the complete encryption/decryption process. Especially for asymmetric keys; the most important thing is, even if the user is using a 128-bit symmetric key, although the number of bits encrypted output will vary depending on different algorithms, but at the end the length of the packet is a symmetric key, that is 32 hexadecimal digits, For accurate user input it is a challenging and complicated thing. The encryption/decryption mode of authentication is not mainly in the hardware token applications [<xref ref-type="bibr" rid="scirp.73043-ref19">19</xref>] . Parallel computing requires token authentication operation mode, the authenticator and the authenticator use the same factors separately according to a certain algorithm (hash encryption) operation, and then compares each other. Although it is based on parallel computing methodology of hash algorithm for its easy to use system resources and needs to oppose to 1/decryption less computing speed into the mainstream embedded system design approach, but it is not based on the full implementation of the digital signature manner, in law, it does not have auditable significance. The system is based on DSA [<xref ref-type="bibr" rid="scirp.73043-ref20">20</xref>] [<xref ref-type="bibr" rid="scirp.73043-ref21">21</xref>] (Digital Signature Algorithm) as authentication, is a total non-factor-based authentication method are inherently non-repudiation, and the system has been incorporated undeniable factor time-stamp, which implement a strong auditable login authentication system. Meanwhile, the implementation of the system to take half the software effectively solves the speed problem that DSA brought [<xref ref-type="bibr" rid="scirp.73043-ref22">22</xref>] .</p></sec><sec id="s3_3"><title>3.3. Experimental Results</title><p>Input information: “AA”, it’s ASCII code is “616263”, after filling the message shows in <xref ref-type="table" rid="table1">Table 1</xref>.</p><p>As show in the table, arbitrarily length information will be filled into affixed length information.</p><p>When after extending, W0, W1 … W67 are as follow <xref ref-type="table" rid="table2">Table 2</xref>.</p><p>The filled message after extending is show in <xref ref-type="table" rid="table2">Table 2</xref>. The table reflects that the message is messy. Same as above, W0’, W1’ … W63’ are as follow <xref ref-type="table" rid="table3">Table 3</xref>.</p><p>After 64 rounds of iterative form 256 bit hash values are as follows.</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> The message after filling</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >61626380</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th></tr></thead><tr><td align="center" valign="middle" >61626380</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td></tr><tr><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td></tr><tr><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td></tr><tr><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000018</td></tr></tbody></table></table-wrap><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> After extending: W<sub>0</sub>, W<sub>1</sub> … W<sub>67</sub></title></caption><table><tbody><thead><tr><th align="center" valign="middle" >61626380</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th></tr></thead><tr><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td></tr><tr><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000018</td><td align="center" valign="middle" >9092e200</td><td align="center" valign="middle" >00000000</td></tr><tr><td align="center" valign="middle" >0000c060</td><td align="center" valign="middle" >719c70ed</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >8001801f</td><td align="center" valign="middle" >939f7da9</td><td align="center" valign="middle" >00000000</td></tr><tr><td align="center" valign="middle" >2c6fa1f9</td><td align="center" valign="middle" >adaaef14</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >0001801e</td><td align="center" valign="middle" >9a965f89</td><td align="center" valign="middle" >49710048</td></tr><tr><td align="center" valign="middle" >23ce86a1</td><td align="center" valign="middle" >b2d12f1b</td><td align="center" valign="middle" >e1dae338</td><td align="center" valign="middle" >f8061807</td><td align="center" valign="middle" >055d68be</td><td align="center" valign="middle" >86cfd481</td></tr><tr><td align="center" valign="middle" >1f447d83</td><td align="center" valign="middle" >d9023dbf</td><td align="center" valign="middle" >185898e0</td><td align="center" valign="middle" >e0061807</td><td align="center" valign="middle" >050df55c</td><td align="center" valign="middle" >cde0104c</td></tr><tr><td align="center" valign="middle" >a5b9c955</td><td align="center" valign="middle" >a7df0184</td><td align="center" valign="middle" >6e46cd08</td><td align="center" valign="middle" >e3babdf8</td><td align="center" valign="middle" >70caa422</td><td align="center" valign="middle" >0353af50</td></tr><tr><td align="center" valign="middle" >a92dbca1</td><td align="center" valign="middle" >5f33cfd2</td><td align="center" valign="middle" >e16f6e89</td><td align="center" valign="middle" >f70fe941</td><td align="center" valign="middle" >ca5462dc</td><td align="center" valign="middle" >85a90152</td></tr><tr><td align="center" valign="middle" >76af6296</td><td align="center" valign="middle" >c922bdb2</td><td align="center" valign="middle" >68378cf5</td><td align="center" valign="middle" >97585344</td><td align="center" valign="middle" >09008723</td><td align="center" valign="middle" >86faee74</td></tr><tr><td align="center" valign="middle" >2ab908b0</td><td align="center" valign="middle" >4a64bc50</td><td align="center" valign="middle" >864e6e08</td><td align="center" valign="middle" >f07e6590</td><td align="center" valign="middle" >325c8f78</td><td align="center" valign="middle" >accb8011</td></tr><tr><td align="center" valign="middle" >e11db9dd</td><td align="center" valign="middle" >b99c0545</td><td align="center" valign="middle" ></td><td align="center" valign="middle" ></td><td align="center" valign="middle" ></td><td align="center" valign="middle" ></td></tr></tbody></table></table-wrap><table-wrap id="table3" ><label><xref ref-type="table" rid="table3">Table 3</xref></label><caption><title> After extending: W0’, W1’ … W63’</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >61626380</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th><th align="center" valign="middle" >00000000</th></tr></thead><tr><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000000</td><td align="center" valign="middle" >00000018</td></tr><tr><td align="center" valign="middle" >9090e200</td><td align="center" valign="middle" >8001801f</td><td align="center" valign="middle" >93937baf</td><td align="center" valign="middle" >719c70ed</td><td align="center" valign="middle" >2c6fa1f9</td><td align="center" valign="middle" >2dab6f0b</td></tr><tr><td align="center" valign="middle" >939f7da9</td><td align="center" valign="middle" >0001801e</td><td align="center" valign="middle" >b6f9fe70</td><td align="center" valign="middle" >e4dbef5c</td><td align="center" valign="middle" >23ce86a1</td><td align="center" valign="middle" >b2d0af05</td></tr><tr><td align="center" valign="middle" >7b4cbcb1</td><td align="center" valign="middle" >b177184f</td><td align="center" valign="middle" >2693ee1f</td><td align="center" valign="middle" >341efb9a</td><td align="center" valign="middle" >fe9e9ebb</td><td align="center" valign="middle" >e4dbef5c</td></tr><tr><td align="center" valign="middle" >23ce86a1</td><td align="center" valign="middle" >b2d0af05</td><td align="center" valign="middle" >7b4cbcb1</td><td align="center" valign="middle" >b177184f</td><td align="center" valign="middle" >2693ee1f</td><td align="center" valign="middle" >341efb9a</td></tr><tr><td align="center" valign="middle" >fe9e9ebb</td><td align="center" valign="middle" >210425b8</td><td align="center" valign="middle" >1d05f05e</td><td align="center" valign="middle" >66c9cc86</td><td align="center" valign="middle" >1a4988df</td><td align="center" valign="middle" >14e22df3</td></tr><tr><td align="center" valign="middle" >a5b9c955</td><td align="center" valign="middle" >a7df0184</td><td align="center" valign="middle" >6e46cd08</td><td align="center" valign="middle" >e3babdf8</td><td align="center" valign="middle" >70caa422</td><td align="center" valign="middle" >0353af50</td></tr><tr><td align="center" valign="middle" >47d91983</td><td align="center" valign="middle" >93937baf</td><td align="center" valign="middle" >6b4b3854</td><td align="center" valign="middle" >2e5aadb4</td><td align="center" valign="middle" >d5736d77</td><td align="center" valign="middle" >a48caed4</td></tr><tr><td align="center" valign="middle" >6379de7d</td><td align="center" valign="middle" >da9ace80</td><td align="center" valign="middle" >97c00c1f</td><td align="center" valign="middle" >3e2d54f3</td><td align="center" valign="middle" >a263ee29</td><td align="center" valign="middle" >12f15216</td></tr><tr><td align="center" valign="middle" >49e260d5</td><td align="center" valign="middle" >6753d7d5</td><td align="center" valign="middle" >864e6e08</td><td align="center" valign="middle" >18e587c8</td><td align="center" valign="middle" ></td><td align="center" valign="middle" ></td></tr></tbody></table></table-wrap><p>66c7f0f4 62eeedd9 d1f2d46b dc10e4e2 4167c487 5cf2f7a2 297da02b 8f4b8e0</p><p>According to local time, 2016, 4, 24, 14:54:25, get the initial value of dynamic password OTP = 62e229, convert it into decimal OTP’ = 6480937, finally get the truncated dynamic password P = 048093.</p></sec></sec><sec id="s4"><title>4. Conclusion</title><p>In network management, security management is a critical task during communication and transmission. To achieve high end security technology, hardware and software devices are developed recently by using firewalls. Still authentication technology is an important aspect of information security that needs to be addressed. Authentication is the first line of defence against possible attacks from hacker’s. With the rapid developments in authentication security, it has somehow increased security demands and is one of the hot research areas. Dynamic password relatively has many advantages over static password and provides one more layer of security, and provides more security to users with incorporation in the software, which results in improved security and reduces the chances of data loss and hacking [<xref ref-type="bibr" rid="scirp.73043-ref23">23</xref>] [<xref ref-type="bibr" rid="scirp.73043-ref24">24</xref>] . This paper basically proposed SH3 Algorithm. The basic functionality of SH3 Algorithm is to generate dynamic password by SM3 Hash Algorithm using current time and the identity ID and it varies with time and changes randomly. Coupled with the SM3 hash algorithm security, dynamic password security properties can be further improved, thus it effectively improves network authentication security. Experimental results show the reliability and improved performance of SH3 Hash Algorithm.</p></sec><sec id="s5"><title>Acknowledgements</title><p>The research was partially supported by the National Nature Science Foundation of China (No. 61373084) and the innovation Program of Shanghai Municipal Education Commission (No. 14YZ011).</p></sec><sec id="s6"><title>Cite this paper</title><p>Silue, D.S., Wan, W.G. and Rizwan, M. (2016) Research and Implementation of Time Synchronous Dynamic Password Based on SM3 Hash Algorithm. Open Journal of Applied Sciences, 6, 893-902. http://dx.doi.org/10.4236/ojapps.2016.613077</p></sec></body><back><ref-list><title>References</title><ref id="scirp.73043-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Sandirigama, M., Shimizu, A. and Noda, M.T. (2000) Simple and Secure Password Authentication Protocol (SAS). IEICE Technical Report Office Information Systems, 83, 1363-1365.</mixed-citation></ref><ref id="scirp.73043-ref2"><label>2</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Stallings</surname><given-names> W. </given-names></name>,<etal>et al</etal>. (<year>2006</year>)<article-title>Cryptography and Network Security: Principles and Practice</article-title><source> IEEE Transactions on Dielectrics &amp; Electrical Insulation</source><volume> 13</volume>,<fpage> 98</fpage>-<lpage>104</lpage>.<pub-id pub-id-type="doi"></pub-id></mixed-citation></ref><ref id="scirp.73043-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">De Canniere, C. and Rechberger, C. (2002) Finding SHA-1 Characteristics: General Results and Application. IACR Cryplogye Print Archive, p. 391.</mixed-citation></ref><ref id="scirp.73043-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Wang, X.Y. and Yu, H.B. (2012) How to Break MD5 and Other Hash Function. Lecture Notes in Computer Science, 3494, 19-35.</mixed-citation></ref><ref id="scirp.73043-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Abdalla, M. and Reyzin, L. (2007) A New Forward-Secure Digital Signature Scheme. IEEE International Workshop on Anti-Counterfeiting, Security, Identification, Springer Berlin Heidelberg, 116-129.</mixed-citation></ref><ref id="scirp.73043-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Zou, J., Wu, W.L., Wu, S., Su, B.Z. and Dong, L. (2011) Preimage Attacks on Step-Reduced SM3 Hash Function. Lecture Notes in Computer Science, 7259, 375-390.</mixed-citation></ref><ref id="scirp.73043-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Joan, D. and Vincent, R. (2012) The Design of Rijndael: AES—The Advanced Encryption Standard. Springer Science &amp; Business Media.</mixed-citation></ref><ref id="scirp.73043-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Diffie, W. and Hellman, M.E. (1976) New Directions in Cryptography. IEEE Transactions on Information Theory, 22, 644-654. https://doi.org/10.1109/TIT.1976.1055638</mixed-citation></ref><ref id="scirp.73043-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Peng, F., Qiu, S.S. and Long, M. (2005) A Secure Digital Signature Algorithm Based on Elliptic Curve and Chaotic Mappings. Circuits Systems &amp; Signal Processing, 24, 585-597. 
https://doi.org/10.1007/s00034-005-2409-4</mixed-citation></ref><ref id="scirp.73043-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Sandirigama, M., Shimizu, A. and Noda, M.T. (2011) Simple and Secure Password Authentication Protocol. IEICE Transactions on Communications, 83, 1363-1365.</mixed-citation></ref><ref id="scirp.73043-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Haller, N. (1995) The S/KEY One-Time Password System. Proceedings of the Internet Society Symposium on Network &amp; Distributed Systems, San Diego, February 1995, 151-157.  
https://doi.org/10.17487/rfc1760</mixed-citation></ref><ref id="scirp.73043-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Halevi, S., Hall, W.E. and Jutla, C.S. (2008) The Hash Function Fugue. Submission to Nist.</mixed-citation></ref><ref id="scirp.73043-ref13"><label>13</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Young-Hwa</surname><given-names> A. </given-names></name>,<etal>et al</etal>. (<year>2013</year>)<article-title>Security Improvements of Dynamic ID-based Remote User Authentication Scheme with Session Key Agreement</article-title><source> IEEE Transactions on Consumer Electronics</source><volume> 8</volume>,<fpage> 1072</fpage>-<lpage>1076</lpage>.<pub-id pub-id-type="doi"></pub-id></mixed-citation></ref><ref id="scirp.73043-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Si, J., Jin, C. and Liu, G. (2013) Research and Improvement on the Remote Dynamics Password Authentication Scheme. Computer Applications and Software, 25, 54-55.</mixed-citation></ref><ref id="scirp.73043-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Detchast, P. and Thawatchai, C. (2011) Web Security Improving by Using Dynamic Password Authentication. 2011 International Conference on NetWork and Electronics Engineering IPCSIT, 11, 32-36.</mixed-citation></ref><ref id="scirp.73043-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Wang, B. and Liu, G. (2012) Study and Amend Dynamic Password Authentication Scheme. Computer Engineering and Design, 28, 2806-2808.</mixed-citation></ref><ref id="scirp.73043-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Guo, L., Wang, L. and Li, Q. (2015) Differential Power Analysis of Dynamic Password Token Based on SM3 Algorithm, and Countermeasures. 11th International Conference on Computational Intelligence and Security, Shenzhen, 19-20 December 2015, 354-357.</mixed-citation></ref><ref id="scirp.73043-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Pointcheval, D. and Stern, J. (2000) Security Arguments for Digital Signatures and Blind Signatures. Journal of Cryptology, 13, 361-396. https://doi.org/10.1007/s001450010003</mixed-citation></ref><ref id="scirp.73043-ref19"><label>19</label><mixed-citation publication-type="book" xlink:type="simple">Biryukov, A., Lamberger, M., Mendel, F. and Nikolic, I. (2011) Second-Order Differential Collisions for Reduced SHA-256. In: Lee, D.H. and Wang, X., Eds., Advances in Cryptology—ASIACRYPT 2011, Springer, Berlin, 270-287.  
https://doi.org/10.1007/978-3-642-25385-0_15</mixed-citation></ref><ref id="scirp.73043-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Brosa, A.M. and Figueras, J. (2000) Digital Signature Proposal for Mixed-Signal Circuits. Journal of Electronic Testing, 17, 1041-1050. https://doi.org/10.1109/test.2000.894317</mixed-citation></ref><ref id="scirp.73043-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Goldwasser, S. and Waisbard, E. (2004) Transformation of Digital Signature Schemes into Designated Confirmer Signature Schemes. Theory of Cryptography Conference, Cambridge, 19-21 February 2004, 77-100. https://doi.org/10.1007/978-3-540-24638-1_5</mixed-citation></ref><ref id="scirp.73043-ref22"><label>22</label><mixed-citation publication-type="other" xlink:type="simple">Johnson, D., Menezes, A. and Vanstone, S. (2010) The Elliptic Curve Digital Signature Algorithm (ECDSA). International Journal of Information Security, 1, 36-63.  
https://doi.org/10.1007/s102070100002</mixed-citation></ref><ref id="scirp.73043-ref23"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Song, C., Qu, Z., Blumm, N. and Barabási, A. (2010) Limits of Predictability in Human Mobility. Science, 327, 1018-1021. https://doi.org/10.1126/science.1177170</mixed-citation></ref><ref id="scirp.73043-ref24"><label>24</label><mixed-citation publication-type="other" xlink:type="simple">Haller, N., Metz, C., Nesser, P. and Straw, M. (1998) A One-Time Password System. Network and Distributed System Security Symposium, San Diego, 11-13 March 1998, 98-100.  
https://doi.org/10.17487/rfc2289</mixed-citation></ref></ref-list></back></article>