Stateless Decentralized Authentication Using Segmented ZKPs for Microservices Architectures
Abstract
The growing integration of microservices exacerbates the mounting concern over privacy and trust caused by frequent data leaks and breaches. These systems are inherently decentralized, making them harder to manage, increasing the attack surface, and complicating trust between independently deployed services. Despite these persistent challenges, trust and authentication are often handled using centralized and stateful methods that require storing extensive state information. Existing so-called stateless authentication methods typically shift state storage from the server to the client side rather than detaching from state dependency. To address this challenge, we propose a lightweight, scalable, and truly stateless authentication approach that is non-idempotent and utilizes self-resetting nested Zero-Knowledge Proofs (ZKPs) to eliminate reliance on past actions. This platform anticipates user intentions and rigorously monitors them, ensuring bidirectional operational integrity while preserving privacy. Specifically, the self-resetting ZKP mechanism leverages the dynamic nature of microservices and incorporates random proof segmentation as a random generator to ensure each request is unique. Our tests using the OpenTelemetry Demo confirm its functionality and the independence between requests. Furthermore, security analysis demonstrates comprehensive security through non-idempotent authentication and the uniqueness of proof segmentation for each request.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.