The purpose of this thesis is to describe the setup of a two-factor authentication system at Register.si, which will ensure a greater protection of information. The system consists of a
FreeRADIUS server that takes care of user authentication in connection to the MultiOTP tool, as well as of AuthenticationApi web services that accept user authentication requirements.
The thesis will present an importance of two-factor authentication, as well as offer descriptions of various authentication algorithms and protocols, and security devices.
Concerning two-factor authentication, the username and the password cover the first factor, while a one-time password token generator was chosen as the second factor, as the most appropriate one for
a predetermined criteria.
|