Hawkynt

TOTP

Time-Based One-Time Password algorithm as defined in RFC 6238. Generates time-dependent OTPs using HMAC for two-factor authentication, synchronized by time between client and server with 30-second default window.

Properties

Property Value
Category Special Algorithms
Sub-category One-Time Password
Security status πŸ›‘οΈ Secure
Complexity Beginner
Inventor David M’Raihi, Johan Rydell, Mingliang Pei, Salah Machani
Year 2011
Origin πŸ‡ΊπŸ‡Έ United States
Source algorithms/special/totp.js

Security

Status: πŸ›‘οΈ Secure

No vulnerabilities are recorded for this implementation.

Documentation

References

Test vectors

5 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 β€” RFC 6238 TOTP Test Vector - SHA1 @ 59s (8 digits)

Field Value
key 3132333435363738393031323334353637383930
timestamp 59
timestep 30
digits 8
hashAlgorithm SHA-1
input (empty)
expected 3934323837303832

Vector 2 β€” RFC 6238 TOTP Test Vector - SHA1 @ 1111111109s (8 digits)

Field Value
key 3132333435363738393031323334353637383930
timestamp 1111111109
timestep 30
digits 8
hashAlgorithm SHA-1
input (empty)
expected 3037303831383034

Vector 3 β€” RFC 6238 TOTP Test Vector - SHA1 @ 1234567890s (8 digits)

Field Value
key 3132333435363738393031323334353637383930
timestamp 1234567890
timestep 30
digits 8
hashAlgorithm SHA-1
input (empty)
expected 3839303035393234

Vector 4 β€” RFC 6238 TOTP Test Vector - SHA256 @ 59s (8 digits)

Field Value
key 3132333435363738393031323334353637383930313233343536373839303132
timestamp 59
timestep 30
digits 8
hashAlgorithm SHA-256
input (empty)
expected 3436313139323436

Vector 5 β€” RFC 6238 TOTP Test Vector - SHA512 @ 59s (8 digits)

Field Value
key 31323334353637383930313233343536 37383930313233343536373839303132 33343536373839303132333435363738 39303132333435363738393031323334
timestamp 59
timestep 30
digits 8
hashAlgorithm SHA-512
input (empty)
expected 3930363933393336

← All algorithms