SecureAttend: A Privacy-Preserving Cloud-Based Attendance Management Framework Integrating Zero-Knowledge Proof Authentication and Biometric Verification
Abstract
Conventional attendance management approaches in academic and organisational settings face persistent challenges that include susceptibility to proxy attendance, inadequate protection of biometric credentials, and the absence of privacy-preserving verification mechanisms in cloud-hosted deployments. This paper presents SecureAttend, a cloud-based attendance management framework that addresses these deficiencies through the integration of Zero-Knowledge Proof (ZKP) cryptographic authentication with biometric capture via a ZKTeco K40 Pro fingerprint terminal. The proposed framework employs a challenge-response ZKP protocol that enables users to demonstrate possession of valid authentication credentials without disclosing underlying private keys or biometric templates to the server. Attendance records are encrypted using AES-256 prior to storage in a MongoDB cloud database, while SHA-256 hashing provides tamper-evidence for each record. Session integrity is maintained through JWT-based token management, and access boundaries are enforced via a Role-Based Access Control (RBAC) policy. Functional evaluation across eighteen test scenarios confirmed complete compliance with stated requirements. Security assessment validated correct operation of cryptographic mechanisms, access controls, and audit logging subsystems. Performance benchmarks recorded average API response latencies of approximately 85 milliseconds for authentication requests and 120 milliseconds for attendance marking operations. The results demonstrate that ZKP authentication can be deployed effectively in real-world attendance management contexts, offering measurable improvements in privacy, integrity, and resistance to credential-based attacks compared with conventional approaches.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.