# PayPal Security Key.  How does it work?

**URL:** <https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248>\
**Category:** Factual Questions\
**Created:** [July 12, 2008, 5:48pm UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248 "2008-07-12T17:48:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![retusaf99](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@retusaf99](https://boards.straightdope.com/u/retusaf99)\
**Post date:** [July 12, 2008, 5:48pm UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/1 "2008-07-12T17:48:00Z")

</div>

PayPal sent me an offer for a small digital security key. It generates a 6 digit number, apparently good for 30 seconds (or it changes after 30 sec…not sure).

I use it to sign into both eBay and PayPal, along with the regular user name and password. So far, it’s worked fine. But what happens when the battery dies?

The PayPal web site is pretty vague on just what happens, other than send them $5 and they send you one of the keys, postage paid.

I’m curious about the technology behind it. Is this some kind of time-based calculation? (I really want to type “algorithm”, but that makes me think of Al Gore…)

Doug

---

<div class="post-metadata">

**Author:** ![xash](https://avatars.discourse-cdn.com/v4/letter/x/c6cbf5/32.png) [@xash](https://boards.straightdope.com/u/xash)\
**Post date:** [July 12, 2008, 9:28pm UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/2 "2008-07-12T21:28:22Z")

</div>

I believe PayPal offers SecureID hardware tokens.

Flash demo:

> **[RSA](https://www.rsa.com/)**
>
> RSA helps manage your digital risk with a range of capabilities and expertise including integrated risk management, threat detection and response and more.

How does it work? In simple terms, the device uses an algorithm for which the inputs are 1. Time and 2. a key unique to your hardware (e.g. hardware serial number). The output of this combination is the resulting token number. The server uses the same two inputs, and therefore has the same output. If the outputs match, authentication is successful.

See also:

> **[RSA SecurID](https://en.wikipedia.org/wiki/SecurID)**
>
> RSA SecurID, formerly referred to as SecurID, is a mechanism developed by RSA for performing two-factor authentication for a user to a network resource.
> The RSA SecurID authentication mechanism consists of a "token"—either hardware (e.g. a key fob) or software (a soft token)—which is assigned to a computer user and which creates an authentication code at fixed intervals (usually 60 seconds) using a built-in clock and the card's factory-encoded almost random key (known as the "seed"). The seed is...

[http://www.schrankmonster.de/PermaLink,guid,62f14e36-5aaf-4b2a-b470-733fdfcf7e9b.aspx](http://www.schrankmonster.de/PermaLink,guid,62f14e36-5aaf-4b2a-b470-733fdfcf7e9b.aspx)

> **[Yahoo | Mail, Weather, Search, Politics, News, Finance, Sports & Videos](https://www.yahoo.com/)**
>
> Latest news coverage, email, free stock quotes, live scores and video are just the beginning. Discover more every day at Yahoo!

---

<div class="post-metadata">

**Author:** ![racer72](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/racer72/32/3075_2.png) [@racer72](https://boards.straightdope.com/u/racer72)\
**Post date:** [July 12, 2008, 9:32pm UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/3 "2008-07-12T21:32:19Z")

</div>

whoops.

---

<div class="post-metadata">

**Author:** ![retusaf99](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@retusaf99](https://boards.straightdope.com/u/retusaf99)\
**Post date:** [July 13, 2008, 3:51am UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/4 "2008-07-13T03:51:52Z")

</div>

[QUOTE=xash]  
I believe PayPal offers SecureID hardware tokens.

Flash demo:

> **[RSA](https://www.rsa.com/)**
>
> RSA helps manage your digital risk with a range of capabilities and expertise including integrated risk management, threat detection and response and more.

How does it work? In simple terms, the device uses an algorithm for which the inputs are 1. Time and 2. a key unique to your hardware (e.g. hardware serial number). The output of this combination is the resulting token number. The server uses the same two inputs, and therefore has the same output. If the outputs match, authentication is successful.

See also:

> **[RSA SecurID](https://en.wikipedia.org/wiki/SecurID)**
>
> RSA SecurID is a mechanism developed by RSA for performing two-factor authentication for a user to a network resource.
> The RSA SecurID authentication mechanism consists of a "token"—either hardware (e.g. a key fob) or software (a soft token)—which is assigned to a computer user and which creates an authentication code at fixed intervals (usually 60 seconds) using a built-in clock and the card's factory-encoded almost random key (known as the "seed"). The seed is different for each token, and is ...

[http://www.schrankmonster.de/PermaLink,guid,62f14e36-5aaf-4b2a-b470-733fdfcf7e9b.aspx](http://www.schrankmonster.de/PermaLink,guid,62f14e36-5aaf-4b2a-b470-733fdfcf7e9b.aspx)

> **[Yahoo Search - Web Search](https://search.yahoo.com/)**
>
> The search engine that helps you find exactly what you're looking for. Find the most relevant information, video, images, and answers from all across the Web.

[/QUOTE]

Thank you. That’s pretty much what I thought. I just wan’t sure how the time factor figured in. Still, kinda a cool gizmo…

Doug

---

<div class="post-metadata">

**Author:** ![retusaf99](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@retusaf99](https://boards.straightdope.com/u/retusaf99)\
**Post date:** [July 13, 2008, 4:03am UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/5 "2008-07-13T04:03:12Z")

</div>

[QUOTE=retusaf99]  
Thank you. That’s pretty much what I thought. I just wan’t sure how the time factor figured in. Still, kinda a cool gizmo…

Doug  
[/QUOTE]  
It has been a long day. That “wan’t” in the previous post is missing an “s”, and should read “wasn’t.”

My apologies to sharp-eyed readers that offends. Not my first mistake, probably not my last (unless I die tonight).

🙂

Doug

---

<div class="post-metadata">

**Author:** ![xash](https://avatars.discourse-cdn.com/v4/letter/x/c6cbf5/32.png) [@xash](https://boards.straightdope.com/u/xash)\
**Post date:** [July 13, 2008, 8:01am UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/6 "2008-07-13T08:01:49Z")

</div>

[QUOTE=retusaf99]  
I just wan’t sure how the time factor figured in.  
[/QUOTE]  
In case you’re still unclear about how time is factored in (and if you’re already clear, then for the benefit of others reading this thread)…

Let’s assume for simplicity’s sake, that we have:

1. Input 1 (Time)
2. Input 2 (Serial Number)
3. Algorithm

All 3 of which are available to the device. Time is constantly changing, but at any given instance the current value is available as Input 1. Serial Number does not change and the value is also available. The algorithm is programmed into the device.

Now, let’s assume that the algorithm is something as simple as “Add Input 1 to Input 2, then multiply by 5 and add 250 to the result” (it’s not really this simple, it’s actually AES encryption)

Let’s say the time on the device is currently 01:00:53 on Sunday July 13, 2009. This can be stored as “20090713010053” (note that this is not really how computers store time, but I’m just using this for illustration purposes). So, Input 1 = 20090713010053

Now, let’s assume Input 2 (Serial Number for your specific hardware unit) is “44893271231987”

So,  
Input 1 = 20090713010053  
Input 2 = 44893271231987

Algorithm = (((Input 1 + Input 2) x 5) + 250)

Result = ((((20090713010053 + 44893271231987) x 5) + 250)  
Result = 324919921210450 (this is what displays on your unit)

The server uses the same inputs and algorithm to reach the same result. The authentication server compares what you see on your unit to what it calculated.

---

<div class="post-metadata">

**Author:** ![retusaf99](https://avatars.discourse-cdn.com/v4/letter/r/46a35a/32.png) [@retusaf99](https://boards.straightdope.com/u/retusaf99)\
**Post date:** [July 13, 2008, 5:42pm UTC](https://boards.straightdope.com/t/paypal-security-key-how-does-it-work/456248/7 "2008-07-13T17:42:15Z")

</div>

TY!!

Doug
