Experimental Study of DIGIPASS GO3 and the Security of Authentication
Igor Semaev

TL;DR
This study analyzes DIGIPASS GO3's OTP system, revealing vulnerabilities that allow forgery attacks with a higher success probability than expected, posing significant security risks for organizations.
Contribution
It reconstructs the token's synchronization, algorithm, and protocol, demonstrating vulnerabilities and potential for large-scale account compromises.
Findings
OTP predictability is higher than expected
Forgery attack success probability is approximately 8^-5
Potential for over 100 compromised accounts annually in small organizations
Abstract
Based on the analysis of -digit one-time passwords(OTP) generated by DIGIPASS GO3 we were able to reconstruct the synchronisation system of the token, the OTP generating algorithm and the verification protocol in details essential for an attack. The OTPs are more predictable than expected. A forgery attack is described. We argue the attack success probability is . That is much higher than which may be expected if all the digits are independent and uniformly distributed. Under natural assumptions even in a relatively small bank or company with customers the number of compromised accounts during a year may be more than .
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
