Journal of Modern Technology and Engineering

Journal of Modern Technology and Engineering

ISSN Online: 2519-4836

Journal of Modern Technology and Engineering is devoted to the publication of original investigations, observations, scholarly inquiries, and reviews in the various branches of technology and engineering. All published papers are peer-reviewed. It covers cutting edge developments in modern technology and engineering from around the globe. This widely referenced publication helps digital investigators remain current on new technologies, useful tools, relevant research, investigative techniques, and methods for handling security breaches.The journal is published three times in a year.

Share
Abstract

In modern authentication frameworks, commercially deployed external Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) services and conventional passwords are widely employed as a dual-layer authentication mechanism. However, from a cryptographic perspective, this sequential architecture introduces an architectural decoupling that may weaken the overall security guarantees of the authentication process, since password verification and human verification remain operationally independent. Consequently, user credentials may still be exposed through network interception or database compromise even when the CAPTCHA stage is successfully completed. Furthermore, the effectiveness of conventional CAPTCHA systems is increasingly challenged by advances in machine learning and computer vision. Commercial CAPTCHA services may also process browser-, device-, and interaction-related signals for automated risk assessment. Such processing creates data-protection considerations under applicable legal frameworks, including the GDPR and Turkiye’s Personal Data Protection Law No. 6698. To address these limitations, this paper proposes a zero-dependency hybrid authentication architecture that integrates a Schnorr-style Zero-Knowledge Proof (ZKP) with a localized Human-Interactive Proof (HIP) mechanism. The proposed protocol keeps the password-derived secret scalar strictly on the client side and stores only the public verifier V = gx (mod p) on the server. During authentication, the active CAPTCHA context is incorporated through a session coefficient h, enabling the server to derive the public hybrid verifier Vhybrid = Vh (mod p) without learning the password-derived secret. The final challenge is generated from a Fiat–Shamir transcript containing the session identifier, server nonce, hybrid verifier, and commitment point, thereby cryptographically binding each authentication proof to the active session and preventing replay attacks under the adopted threat model. Experimental evaluation based on Selenium-driven automated brute-force simulations, together with an analytical assessment of computational overhead, communication cost, and per-request implementation performance, demonstrates that the proposed architecture effectively mitigates password-only automation, stale-session replay, and invalid proof submissions while preserving the completeness, knowledge soundness, and honest-verifier zero-knowledge properties inherited from the Schnorr authentication protocol. The resulting framework provides a privacy-preserving and locally deployable authentication solution for environments in which reliance on external CAPTCHA providers is undesirable.



Copy
  • View 47
  • Downloads 13
  • Saveds 0
  • Citations (Crossref) 0