Two-Factor Authentication Protocol Based on Zero-Knowledge Proof Using Elliptic Curves
摘要
The use of open communication channels presents opportunities for malicious attacks. Therefore, ensuring secure user interactions requires methods that enable one party (the verifier) to confirm the identity of the other party (the prover). In challenge-response protocols, an adversary who has control over the communication channel can issue tailored requests and, by analyzing the responses, potentially acquire confidential information. To mitigate this risk, zero-knowledge proof protocols are employed, which allow the verification of a statement’s validity without revealing any further details about the statement itself. The purpose of the article is to design a cryptographic protocol for implementing two-factor authentication based on elliptic curves GF(p), GF(2m), GF(3m) integrating biometric information and the private key user’s, seeks to enhance security and reducing the time required for the authentication process. The object of the study’s objective is to evaluate and confirm the effectiveness of the suggested zero-knowledge proof cryptographic protocol against adversarial threats. The proposed protocol was modeled using the High-Level Protocol Specification Language, with model validation and protocol verification conducted via the Security Protocol Animator tool for the automated validation of internet security protocols and applications. The cryptographic protocol was further verified using the software tools On-the-Fly Model Checker and Constraint Logic-based Attack Searcher. The scientific novelty of the presents a groundbreaking cryptographic protocol for two-factor authentication that applies zero-knowledge proof on elliptic curves GF(p), GF(2m), GF(3m) utilizing biometric information and the user’s private key. This solution reduces protocol parameters significantly while improving security by making computational attacks more difficult.