Transforming Digital Identity through Smart Contract as Identity
Abstract
Password-based authentication remains vulnerable due to the centralized storage of passwords on servers. Even with strong user passwords, breaches in the servers can compromise identities. To address this, we outline a smart-contract-as-identity approach, where users are identified by the smart contract address instead of their public keys. If private keys are compromised, users can change their keys directly in the smart contract without needing to change their identity, demonstrating the resilience of our proposal. We also offer both single-key and multi-key signature options, showing flexibility in tuning the security/performance trade-off. Additionally, we create an easy-to-use cryptocurrency wallet-like user interface to enhance usability. Our early analysis shows that this smart contract design is fully deployable in the blockchain network and generates low processing delays. We believe that this research helps make signature-based authentication user-friendly, ultimately paving the way for a passwordless future.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.