Search papers, labs, and topics across Lattice.
This study develops a quantum-safe web service architecture utilizing Time-Based One-Time Passwords (TOTPs) to enhance security in automated connections and system interoperability. By integrating Transport Layer Security (TLS) and HyperText Transfer Protocol Secure (HTTPS) with Post-Quantum Cryptography (PQC), the architecture ensures secure transmission management. Experimental evaluations of various hashing algorithms, including SHA-2, SHA-3, Ascon-Hash256, and SM3, reveal significant differences in computational performance, informing future web service deployments.
Quantum-safe web services can be achieved using TOTPs, ensuring robust security against future quantum threats.
One-Time Passwords (OTPs) have become a common option for multi-factor authentication in several applications. For instance, during website login processes, OTPs are often used in conjunction with traditional text-based usernames and passwords to verify whether the access request originates from a legitimate human user rather than an automated agent. However, in scenarios involving automated connections and system-to-system interoperability, Time-Based One-Time Passwords (TOTPs) may be required to establish secure connections and access Web Services (WSs). Therefore, this study focuses on exploring the development of a quantum-safe web service architecture. The proposed approach achieves transmission security management by implementing Transport Layer Security (TLS) and HyperText Transfer Protocol Secure (HTTPS) based on Post-Quantum Cryptography (PQC). Furthermore, web service security management is realized through the construction of keyed-Hash Message Authentication Code (HMAC)-driven TOTPs. Within the experimental environment, this study evaluates and compares the computational performance of the Secure Hash Algorithm-2 (SHA-2), SHA-3, Ascon-Hash256, and SM3. The required computation time under different hardware resource conditions is analyzed for future web service deployment.