Enhanced Private key Synchronization Mechanism Security in Passkeys System Based on Elliptic Curve Diffie-Hellman and Zero-Knowledge Proofs
- EPJ Web of Conferences, International Conference on Information Systems and Communication Technologies (ICISCT’25) , 1 (380) : 1-13
Résumé
Based on asymmetric cryptography, Passkeys Systems are a secure authentication method that can serve as an alternative to traditional authentication methods, such as usernames and passwords. In this paper, we propose a secure approach to enhance private key synchronization mechanisms in passkeys systems. Our secure service is based on Elliptic Curve Diffie-Hellman protocol and Zero-Knowledge Proofs in a peer-to-peer environment. Following a critical analysis of existing works, which highlights recurrent vulnerabilities related to authentication and confidentiality, we introduce a robust architecture using mutual identity verification, secure session key generation and encrypted passkey transfer. The security of our proposed protocol is assessed through a dual approach: an informal analysis based on potential attack modeling, and a formal validation using ProVerif and Scyther tools. The results demonstrate enhanced resistance to replay attacks, man-in-the-middle attacks, message modification, and identity impersonation, while ensuring optimized performance in terms of computational and communication costs.
Mots-clés
Elliptic Curve Diffie-Hellman, Zero-Knowledge Proofs, Informal Analysis, Formal Analysis, Security