OpenTracker USB User’s Manual
10
10.
Authentication
In addition to the security authorization list, remote access to the tracker can be
controlled through a more secure one-time password mechanism. This
mechanism is enabled by setting
PWAUTH ON
.
To set up one-time password authentication, use the command
SECRET
followed
by a pass phrase of at least 16 characters. The device will use this pass phrase to
generate a 128-bit key that is stored in nonvolatile memory. The password
sequence counter is set to 0 when the key is created.
The
PASSLIST
command can then be used to generate a list of 4-character one-time
passwords, each listed with a unique sequence number. These passwords must
be used in the specified order. You can print out this list and cross off each
password as it’s used.
To use a password, append it to the
CMD
prefix at the start of the command
message. For example, if the next valid password is ‘SBCY’, the message
“
CMDSBCY VERSION
” will execute the
VERSION
command.
While it should be virtually impossible for someone to determine the next
password without knowing your pass phrase, the system is not foolproof. Be
sure not to use the same pass phrase on two different devices, because an
eavesdropper who hears a password used on one device (or who retrieves an old
message from an online database) could potentially use the same password on
the other unit.
Also, should a valid password be sent without being received by the target
device, an eavesdropper would know the next valid password. If you are unsure
of being able to reach the target device, send an unauthenticated message or
query first and make sure you get a reply.
cmd:secret The quick brown fox jumps over the lazy dog.
Set.
cmd:passlist 24
0:C0EP 1:U60T 2:8JES 3:BVBN 4:Z2ZC 5:TEAR 6:VA5S 7:EV1F
8:JCBX 9:NE8G 10:NAAM 11:P1Y8 12:ZJ59 13:H654 14:KSBB 15:PDM8
16:VM89 17:GTNW 18:CW52 19:B7ZX 20:X4DF 21:Z5HF 22:CNNU 23:A8FS