Securing Digital Identity in the Zero Trust Architecture: A Blockchain Approach to Privacy-Focused Multi-Factor Authentication

被引:4
|
作者
Rivera, Javier Jose Diaz [1 ]
Muhammad, Afaq [2 ]
Song, Wang-Cheol [3 ]
机构
[1] Ctr Tecnol Telecomunicac Catalunya CTTC, Barcelona 08860, Spain
[2] Middle East Coll, Dept Comp & Elect Engn, Muscat 124, Oman
[3] Jeju Natl Univ, Dept Elect Engn, Jeju 63243, Jejudo, South Korea
基金
新加坡国家研究基金会;
关键词
Authentication; Blockchains; Security; Zero Trust; Smart contracts; Reliability; Servers; Blockchain; decentralization; MFA; ZKP; zero trust; CHALLENGES; NETWORKS;
D O I
10.1109/OJCOMS.2024.3391728
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
As network systems advance and become more sophisticated, the associated security challenges grow more complex. The zero trust model emerges as a new paradigm to address this, significantly emphasizing robust and continuous identity verification. Multi-factor authentication (MFA) methods have become crucial for enhancing authentication security within this framework. Additionally, the integration of blockchain technology is increasingly recognized for its potential to strengthen identity trustworthiness further, complementing the zero trust approach by providing a more secure and transparent identity verification process. However, privacy concerns remain, especially in public blockchain environments where personal data is vulnerable to inadvertent exposure. Also, using centralized servers for authentication, even in systems integrated with blockchain, presents the risk of creating single points of failure. This paper introduces a privacy-preserving MFA system that harnesses the decentralized capabilities of blockchain technology to enable a Distributed Authentication Mechanism (DAM) as a network of authenticators for enhancing the reliability of the authentication process. This system utilizes blockchain-based Zero-Knowledge Proofs (ZKP) as a privacy mechanism to prove the knowledge of a One-Time Password (OTP). This approach not only ensures the authenticity of the proof authenticity but also confirms the identity of the prover. In the final stage of the MFA process, non-transferable, non-fungible tokens (NFTs) are employed as authentication tokens for identity verification. Our experimental results and comparative security analyses suggest a relevant contribution to secure, private, and dependable MFA framework research.
引用
收藏
页码:2792 / 2814
页数:23
相关论文
共 3 条
  • [1] BAuth-ZKP-A Blockchain-Based Multi-Factor Authentication Mechanism for Securing Smart Cities
    Ahmad, Md. Onais
    Tripathi, Gautami
    Siddiqui, Farheen
    Alam, Mohammad Afshar
    Ahad, Mohd Abdul
    Akhtar, Mohd Majid
    Casalino, Gabriella
    SENSORS, 2023, 23 (05)
  • [2] Beyond passwords: A multi-factor authentication approach for robust digital security
    Simha, R. Keerthan
    Raghavan, H. K.
    Prabhu, Akshatha
    Joshi, Pallavi
    INTERNET TECHNOLOGY LETTERS, 2025, 8 (02)
  • [3] A Blockchain Implementation for Configurable Multi-Factor Challenge-Set Self-Sovereign Identity Authentication
    Norta, Alex
    Kormiltsyn, Alexandr
    Udokwu, Chibuzor
    Dwivedi, Vimal
    Aroh, Sunday
    Nikolajev, Ignas
    2022 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2022), 2022, : 455 - 461