215
IoT Challenges
11.3 Authentication Using OTP Validation
The IoT apps require the establishment of more steps to recognize the relevant appliances.
Keeping this in mind, the illustrated work has been proposed for applying the concept
of using one time password (OTP) as a validation criterion so that only the users who are
eligible to or authorized for logging into the system can do so.
With the help of this procedure, only the users who are authorized to do so would be
able to initiate the transmission and reception of the information after booting of the
system. The description is illustrated in Figure 11.3 [2].
The system accesses the IoT broker application by sending OTP request after booting
with the help of regular Message Queue Telemetry Transport (MQTT) messaging.
The IoT app creates an OTP, delivers that to the system admin individually, and notifies
it to the system. Once the OTP is entered into the system, it is sent to the broker application.
The broker application then authenticates the OTP intimated by the system and responds
with a notification of the successful or failed message (usually invalid OTP or session timeout) back to the system. There is an allowance of trying the OTP validation again which
depends on the number in the configuration of the retry counter. This further generates
two cases:
1. Successful OTP authentication even on retrying: This results in the shutting down of
the application.
2. The inability of OTP validation: This results in skipping of the OTP validation after
initiation.
Access gateway
Send first data to
Watson IoT platform
Device
Start up the device
Watson IoT
platform
Internet
Submit OTP
Register the device
1
Carrier
Enter OTP
Send OTP
4
6
3
5
2
FIGURE 11.3
The switching on and switching off of OTP authentication with the help of system property.
IoT Challenges
11.3 Authentication Using OTP Validation
The IoT apps require the establishment of more steps to recognize the relevant appliances.
Keeping this in mind, the illustrated work has been proposed for applying the concept
of using one time password (OTP) as a validation criterion so that only the users who are
eligible to or authorized for logging into the system can do so.
With the help of this procedure, only the users who are authorized to do so would be
able to initiate the transmission and reception of the information after booting of the
system. The description is illustrated in Figure 11.3 [2].
The system accesses the IoT broker application by sending OTP request after booting
with the help of regular Message Queue Telemetry Transport (MQTT) messaging.
The IoT app creates an OTP, delivers that to the system admin individually, and notifies
it to the system. Once the OTP is entered into the system, it is sent to the broker application.
The broker application then authenticates the OTP intimated by the system and responds
with a notification of the successful or failed message (usually invalid OTP or session timeout) back to the system. There is an allowance of trying the OTP validation again which
depends on the number in the configuration of the retry counter. This further generates
two cases:
1. Successful OTP authentication even on retrying: This results in the shutting down of
the application.
2. The inability of OTP validation: This results in skipping of the OTP validation after
initiation.
Access gateway
Send first data to
Watson IoT platform
Device
Start up the device
Watson IoT
platform
Internet
Submit OTP
Register the device
1
Carrier
Enter OTP
Send OTP
4
6
3
5
2
FIGURE 11.3
The switching on and switching off of OTP authentication with the help of system property.
