A Hybrid Zero-Knowledge Proof and Human Interaction Proof Protocol for Secure Authentication and the Prevention of Automated Brute-Force Attacks
Abstract
Modern authentication architectures contain structural vulnerabilities against automated credential stuffing and server-side data breaches. Traditional solutions rely on the transmission of raw or hashed passwords over the network; for bot defense, they position third-party Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) services, which may violate user privacy and create institutional dependencies, as an illusion of two-factor authentication (2FA). This situation raises a critical research question in cybersecurity: How can an integrated cryptographic shield be constructed that is independent of user-privacy-invasive mechanisms and external data authorities, while preventing autonomous bots from targeting the identity and human-verification layers separately?In response to this question, this paper presents a zero-dependency, original, and hybrid protocol that integrates a Zero-Knowledge Proof (ZKP) based on the Schnorr authentication scheme with a local Human Interaction Proof (HIP) mechanism. The main advantage of the proposed architecture is that it mathematically seals the user’s secret credential together with a dynamically generated one-time CAPTCHA token on the client side using the SHA-256 function, thereby transforming the verification process into an indivisible atomic “Hybrid Secret.” In this way, the transmission of password hashes over the network is completely eliminated, and the server evaluates only the mathematical validity of the proof under the Discrete Logarithm Problem (DLP) assumption.Experimental results obtained through Selenium-based automated brute-force attack simulation engines demonstrate that the system provides complete blocking against automated threat vectors. Dynamic one-time nonce mutation immediately invalidates the derived client response, even in extreme scenarios where an attacking bot obtains the correct password string and solves the CAPTCHA image, thereby mathematically defeating brute-force and replay attacks. Furthermore, the autonomous structure of the proposed protocol, with no dependency on third-party analytics services, opens the way for a highly secure and local authentication architecture for internet-isolated critical infrastructures.In this study, the theoretical and mathematical foundations of the proposed protocol are presented, the stages constituting its life cycle are methodologically explained, and Selenium-based experimental simulation results together with telemetry log analyses are detailed.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.