Guillou-quisquater protocol for user authentication based on zero knowledge proof

Kusnardi, Kevin and Gunawan, Dennis (2019) Guillou-quisquater protocol for user authentication based on zero knowledge proof. TELKOMNIKA Telecommunication, Computing, Electronics and Control, 17 (2). ISSN 1693-6930

Full text not available from this repository.

Abstract

Authentication is the act of confirming the validity of someone’s personal data. In the traditional authentication system, username and password are sent to the server for verification. However, this scheme is not secure, because the password can be sniffed. In addition, the server will keep the user’s password for the authentication. This makes the system vulnerable when the database server is hacked. Zero knowledge authentication allows server to authenticate user without knowing the user’s password. In this research, this scheme was implemented with Guillou-Quisquater protocol. Two login mechanisms were used: file-based certificate with key and local storage. Testing phase was carried out based on the Open Web Application Security Project (OWASP) penetration testing scheme. Furthermore, penetration testing was also performed by an expert based on Acunetix report. Three potential vulnerabilities were found and risk estimation was calculated. According to OWASP risk rating, these vulnerabilities were at the medium level.

Item Type: Article
Keywords: cryptography; guillou-quisquater; security; user authentication; zero knowledge proof;
Subjects: 000 Computer Science, Information and General Works > 000 Computer Science, Knowledge and Systems > 005 Computer Programming
000 Computer Science, Information and General Works > 000 Computer Science, Knowledge and Systems > 006 Special Computer Methods
Divisions: Faculty of Engineering & Informatics > Informatics
Depositing User: Administrator UMN Library
Date Deposited: 08 Oct 2021 01:45
Last Modified: 08 Oct 2021 01:45
URI: https://kc.umn.ac.id/id/eprint/18581

Actions (login required)

View Item View Item