Skip to main navigation Skip to search Skip to main content

Authentification continue par le biais de justificatifs vérifiables sur les blockchains

Translated title of the thesis: Continuous authentication using verifiable credentials on blockchains
  • Kamyar Rostami

Student thesis: Master's thesisMaster in Engineering: Engineering

Abstract

As a discipline in the field of security science, authentication has always proven to be one of the most challenging problems to solve. Both weak authentication methods, such as traditional cryptosystems and more modern biometric-based authentication, require user interaction, despite their significant improvements over the past few decades. According to the results of surveys conducted on smartphone users by the PEW Research Center in 2017, more than 28% of users choose not to activate a screen lock or any other security feature on their phone because they perceive it as an inconvenient method of user authentication due to its intrusiveness [8]. As a result, non-intrusive authentication methods are preferred in day-to-day situations. On the other hand, continuous and non-intrusive authentication methods have not yet reached the same level of security as conventional authentication methods. Using blockchain technology and the most recent industry standards for verifiable credentials, this article makes a proposal for a safe and non-intrusive user authentication system that can be implemented on mobile devices. In addition, we improved the selective disclosure of information by enhancing the proof generation and validation using a Merkle tree. This allowed us to better control the information that was made public. In addition, as our use cases require the verification of multiple proofs at once, we have implemented a multi-proof Merkle tree generation and verification process in order to reduce the computation time and the cost. We have put our system into action, and the results demonstrate that it is safe and user-friendly enough to be used as a reliable authentication method. Furthermore, this research advances the system by substituting the traditional Merkle tree with the Verkle tree, resulting in reduced proof sizes. In terms of security, the implementation shifts from using JWT to PASETO, offering a more robust, efficient, and streamlined continuous authentication framework. As a result of our implementation, we have verified that our system is secure and practical enough to be used on smartphones while maintaining user privacy. Future work aims to further refine this model, enhancing its integration, and expanding its applicability to a wider range of scenarios.
Date30 Jul 2024
Original languageFrench
Awarding Institution
  • École de technologie supérieure
SupervisorKaiwen Zhang (Supervisor)

Cite this

'