Zero-Knowledge User Authentication: An Old Idea Whose Time Has Come

07/29/2019
by   Laurent Chuat, et al.
0

User authentication can rely on various factors (e.g., a password, a cryptographic key, biometric data) but should not reveal any secret or private information. This seemingly paradoxical feat can be achieved through zero-knowledge proofs. Unfortunately, naive password-based approaches still prevail on the web. Multi-factor authentication schemes address some of the weaknesses of the traditional login process, but generally have deployability issues or degrade usability even further as they assume users do not possess adequate hardware. This assumption no longer holds: smartphones with biometric sensors, cameras, short-range communication capabilities, and unlimited data plans have become ubiquitous. In this paper, we show that, assuming the user has such a device, both security and usability can be drastically improved using an augmented password-authenticated key agreement (PAKE) protocol and message authentication codes.

READ FULL TEXT
research
11/03/2017

Design and Analysis of a Secure Three Factor User Authentication Scheme Using Biometric and Smart Card

Password security can no longer provide enough security in the area of r...
research
05/12/2022

Zero-Knowledge Authentication

In the thesis we focus on designing an authentication system to authenti...
research
02/15/2023

FIDO2 the Rescue? Platform vs. Roaming Authentication on Smartphones

Modern smartphones support FIDO2 passwordless authentication using eithe...
research
06/26/2023

MFDPG: Multi-Factor Authenticated Password Management With Zero Stored Secrets

While password managers are a vital tool for internet security, they can...
research
10/14/2022

SealClub: Computer-aided Paper Document Authentication

Digital authentication is a mature field, offering a range of solutions ...
research
10/29/2021

2D-2FA: A New Dimension in Two-Factor Authentication

We propose a two-factor authentication (2FA) mechanism called 2D-2FA to ...
research
08/10/2022

Multi-Factor Key Derivation Function (MFKDF)

We present the first general construction of a Multi-Factor Key Derivati...

Please sign up or login with your details

Forgot password? Click here to reset