Privacy Preserving Authentication Using Zero Knowledge Proofs
Abstract
Conventional authentication techniques, such as one-time passwords and passwords, are extremely susceptible to data breaches, credential theft, and phishing attacks. These vulnerabilities are increased when using shared or public devices. This paper proposes a password-less authentication architecture for various environments and organization based on Zero-Knowledge Proofs in order to overcome these issues. The proposed model ensures that no sensitive credentials are sent or retained by having a user demonstrate that they possess a secret without disclosing it to the server. In doing so, the attack surface linked to traditional login methods is greatly reduced. The framework is meant to be scalable, lightweight and easy to integrate with learning management systems, corporate sites, online test platforms, and university websites.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.