Covert Channels in One-Time Passwords Based on Hash Chains

Download paper


DOI: 10.1145/3424954.3424966
Publication type: Conference paper
Conference: EICC 2020: European Interdisciplinary Cybersecurity Conference
Location: Rennes, France
Online publication date: 2020-11-18


We present a covert channel between two network devices where one authenticates itself with Lamport's one-time passwords based on a cryptographic hash function. Our channel enables plausible deniability. We also present countermeasures to detect the presence of such a covert channel, which are non-trivial because hash values are randomly looking binary strings, so that deviations are not likely to be detected.


  • Jörg Keller
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    FernUniversität in Hagen
    Hagen, Germany
  • Steffen Wendzel
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    Worms University of Applied Science
    Worms, Germany