HMAC-Based One-Time Password algorithm as defined in RFC 4226. Generates time-independent OTPs using HMAC-SHA1 for two-factor authentication, synchronized by counter value between client and server.
| Property | Value |
|---|---|
| Category | Special Algorithms |
| Sub-category | One-Time Password |
| Security status | π‘οΈ Secure |
| Complexity | Beginner |
| Inventor | David MβRaihi, Mihir Bellare, Frank Hoornaert, David Naccache, Ohad Ranen |
| Year | 2005 |
| Origin | πΊπΈ United States |
| Source | algorithms/special/hotp.js |
Status: π‘οΈ Secure
No vulnerabilities are recorded for this implementation.
5 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β RFC 4226 HOTP Test Vector - Counter 0 (6 digits)
| Field | Value |
|---|---|
key |
3132333435363738393031323334353637383930 |
counter |
0 |
digits |
6 |
input |
(empty) |
expected |
373535323234 |
Vector 2 β RFC 4226 HOTP Test Vector - Counter 1 (6 digits)
| Field | Value |
|---|---|
key |
3132333435363738393031323334353637383930 |
counter |
1 |
digits |
6 |
input |
(empty) |
expected |
323837303832 |
Vector 3 β RFC 4226 HOTP Test Vector - Counter 2 (6 digits)
| Field | Value |
|---|---|
key |
3132333435363738393031323334353637383930 |
counter |
2 |
digits |
6 |
input |
(empty) |
expected |
333539313532 |
Vector 4 β RFC 4226 HOTP Test Vector - Counter 7 (7 digits)
| Field | Value |
|---|---|
key |
3132333435363738393031323334353637383930 |
counter |
7 |
digits |
7 |
input |
(empty) |
expected |
32313632353833 |
Vector 5 β RFC 4226 HOTP Test Vector - Counter 8 (8 digits)
| Field | Value |
|---|---|
key |
3132333435363738393031323334353637383930 |
counter |
8 |
digits |
8 |
input |
(empty) |
expected |
3733333939383731 |