A one-time password which is a sequence of 4 to 9 digits.
Modulecrypton-1.0.4Haskell2010
Crypto.OTP
One-time password implementation as defined by the HOTP and TOTP specifications.
Both implementations use a shared key between the client and the server. HOTP passwords are based on a synchronized counter. TOTP passwords use the same approach but calculate the counter as a number of time steps from the Unix epoch to the current time, thus requiring that both client and server have synchronized clocks.
Probably the best-known use of TOTP is in Google's 2-factor authentication.
The TOTP API doesn't depend on any particular time package, so the user needs to supply
the current OTPTime value, based on the system time. For example, using the hourglass
package, you could create a getOTPTime function:
import Time.Systemimport Time.Typeslet getOTPTime = timeCurrent >>= \(Elapsed t) -> return (fromIntegral t :: OTPTime)
Or if you prefer, the time package could be used:
import Data.Time.Clock.POSIXlet getOTPTime = getPOSIXTime >>= \t -> return (floor t :: OTPTime)
- 5 types
- 6 values
- Packagecrypton-1.0.4
- Exports11
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceOTP.hs
The strength of the calculated HOTP value, namely the number of digits (between 4 and 9) in the extracted value.
An integral time value in seconds.
hotp :: (HashAlgorithm hash, ByteArrayAccess key)=> hash-> OTPDigitsNumber of digits in the HOTP value extracted from the calculated HMAC
-> keyShared secret between the client and server
-> Word64Counter value synchronized between the client and server
-> OTPThe HOTP value
resynchronize :: (HashAlgorithm hash, ByteArrayAccess key)=> hash-> OTPDigits-> Word16The look-ahead window parameter. Up to this many values will be calculated and checked against the value(s) submitted by the client
-> keyThe shared secret
-> Word64The current server counter value
-> (OTP, [OTP])The first OTP submitted by the client and a list of additional sequential OTPs (which may be empty)
-> Maybe Word64The new counter value, synchronized with the client's current counter or Nothing if the submitted OTP values didn't match anywhere within the window
Attempt to resynchronize the server's counter value with the client, given a sequence of HOTP values.
totp :: (HashAlgorithm hash, ByteArrayAccess key)=> TOTPParams hash-> keyThe shared secret
-> OTPTimeThe time for which the OTP should be calculated. This is usually the current time as returned by
Data.Time.Clock.POSIX.getPOSIXTime-> OTP
Calculate a totp value for the given time.
Check a supplied TOTP value is valid for the given time, within the window defined by the skew parameter.
Instances1Show
Show h => Show (TOTPParams h)Defined in crypton-1.0.4 · Crypto.OTP
The default TOTP configuration.
mkTOTPParams :: HashAlgorithm hash=> hash-> OTPTimeThe T0 parameter in seconds. This is the Unix time from which to start counting steps (default 0). Must be before the current time.
-> Word16The time step parameter X in seconds (default 30, maximum allowed 300)
-> OTPDigitsNumber of required digits in the OTP (default 6)
-> ClockSkewThe number of time steps to check either side of the current value to allow for clock skew between client and server and or delay in submitting the value. The default is two time steps.
-> Either String (TOTPParams hash)
Create a TOTP configuration with customized parameters.