Non-Interactive Zero-Knowledge Proof based Authentication
Abstract
Passwords are currently the king in online authentication. But passwords come with a lot of baggage - how to use them, store them, hide them, and obfuscate them. Every year, there are plenty of cyber-attacks which involves passwords being stolen. These passwords are stored and transmitted over networks and hence, many mistakes can be made while doing so. In this paper, a relatively new form of authentication is explored - one based on the concept of Zero-Knowledge Proof (ZKP). It further explores how ZKP can provide additional security to the authentication mechanism by taking the transmission of passwords out of the picture. This paper also discusses the Replay attack vulnerability present in the non-interactive implementation of ZKP and proposes a two-fold mitigation strategy against the vulnerability.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.