ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
totp.h File Reference

Time-based one-time passwords, RFC 6238 over RFC 4226 HOTP (PROTOCORE_ENABLE_TOTP). More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

Time-based one-time passwords, RFC 6238 over RFC 4226 HOTP (PROTOCORE_ENABLE_TOTP).

RFC 6238 sec 4.2: "TOTP = HOTP(K, T), where T is an integer and represents the number of time steps between the initial counter time T0 and the current Unix time", with "T = (Current Unix time - T0) / X" under the floor function. X is the time step in seconds and T0 the Unix time step counting starts at, both system parameters of RFC 6238 sec 4.1.

The value under it is RFC 4226 sec 5.2 "HOTP(K,C) = Truncate(HMAC-SHA-1(K,C))": the counter C is hashed high-order byte first, the DT function of RFC 4226 sec 5.3 takes a 31-bit window out of the 20-byte MAC, and that number is reduced mod 10^Digit. The MAC is RFC 2104 sec 2 H(K XOR opad, H(K XOR ipad, C)) over the platform's SHA-1.

The verifier walks the drift window of RFC 6238 sec 6: an OTP is accepted when it matches the receipt time step or any step within a set number of steps forward or backward of it. The provisioning secret arrives as base32 text (RFC 4648 sec 6) and decodes into the K every other call is keyed by.

A caller sets the members a call takes, invokes it through ::Totp, and reads the outcome off the same handle. The module exports one symbol, Totp; everything in totp.c has internal linkage.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file totp.h.