@article {10.3844/jcssp.2019.171.189, article_type = {journal}, title = {Two Factor Authentication for e-Government Services using Hardware-Like One Time Password Generators}, author = {Penna, Giuseppe Della and Frasca, Pietro and Intrigila, Benedetto}, volume = {15}, number = {1}, year = {2019}, month = {Jan}, pages = {171-189}, doi = {10.3844/jcssp.2019.171.189}, url = {https://thescipub.com/abstract/jcssp.2019.171.189}, abstract = {A safe and accessible authentication technique is a prerequisite for any modern e-government application. Two-factor authentication is currently widely adopted, since it alleviates many vulnerabilities of password-based authentication. The majority of e-government systems currently make use of text messages to deliver the second authentication factor, but these messages do not constitute an adequate (secure and reliable) solution. In this paper we show how to use One-Time Passwords (OTP) generated by a per-user, ad-hoc built application installed on a smartphone to support a two-factor authentication scheme specifically targeted to e-government tasks. In particular, we develop a process for the request, generation and distribution of such an application that achieves the same security of OTP hardware devices but avoids the related distribution and management costs, requiring no dedicated hardware and relying on the pre-existing administrative infrastructure. The process is designed to be accessible by any citizen who is able to perform very basic operations on a smartphone.}, journal = {Journal of Computer Science}, publisher = {Science Publications} }