Blockchain-Enabled Verifiable Credential CAPTCHA
摘要
The proposed CAPTCHA moves beyond traditional single-method approaches by integrating multi-factor authentication (MFA) to verify proximity using various technologies, such as Bluetooth, Bluetooth Low Energy (BLE), near-field communication (NFC), biometrics (e.g., facial, voice, or fingerprint recognition), passkey authentication, firmware-level identity, and logical locations like paired devices. To enhance security, users can select multiple registered authentication methods, each linked to a unique, user-specific credential. Verification is streamlined using a Boneh-Lynn-Shacham (BLS) aggregate signature scheme, which combines multiple authentication credentials into a single, verifiable signature. This approach also enables credential aggregation across users, allowing a verifier to authenticate multiple credentials simultaneously. Security analysis confirms the scheme’s resilience against forgery and credential theft. Simulations validate the BLS-based system's efficiency, showing reduced storage and communication requirements, making it well-suited for environments with bandwidth and storage constraints.