Altcoins Talks - Cryptocurrency Forum

Further Discussions => Blockchain Technology => Topic started by: Jee on October 19, 2021, 08:56:06 PM

Title: Velas Technologies: Passwordless Authentication
Post by: Jee on October 19, 2021, 08:56:06 PM
According to research by NordPass, the average user holds 70–80 passwords each. That is a *lot* of passwords to remember. It is no surprise, then, that digital users’ security is a bottleneck and the main goal of hackers — this is why passwordless authentication becomes more and more popular, and more and more vital in a modern digital landscape.

(https://i.imgur.com/Bxn11aL.jpg)

Motivation

Having to create multiple accounts across multiple applications and platforms negatively impacts a product’s attractiveness and convenience. Having a Facebook account, for example, enables users to seamlessly sign into other services with it, reducing friction. Paid services, however, request additional information such as credit card binding which is unavailable during user authorization.

This is why services that implement Passwordless Authentication look increasingly attractive, as they don’t require additional time for authorization.

This technology is promoted by centralized services like Google, Facebook, Apple, Microsoft.


The disadvantages of centralized systems are:

Meanwhile, the blockchain industry is growing rapidly and offers alternative authorization solutions, using seed phrases and the possibility of digital signing which allows you to sign authorization messages and providing all required information about the anonymous account:


Authorization without centralized services is the main blockchain advantage due to exchanging messages between the service and the user’s wallet. Some agents will be needed to connect your wallet to the service, but this is the only function; anyone can create a service, but without the possibility of maliciously affecting other users because all attacks are prevented by cryptographic protocols.



The disadvantages of the decentralized systems are:


Please note that the centralized systems have the advantage of using a local database to store user data and interact with services without having to request additional information.

Each user action requires confirmation in the form of a transaction in decentralized systems. This means that the user has signed a message allowing the action and leading to a change of its state in the block, or a decrease in the balance (also, its state). Existing decentralized passwordless solutions don’t allow making quotas for certain actions that can be performed by a user without additional confirmation.

This feature is required to provide the same level of user experience that we are used to. For example, we want to like videos and leave comments on Youtube without confirming every action. This is possible if the device is authorized and permissions are granted on this service.

Also, users should be able to manage permissions and sessions of authorized devices to control their network activity and ensure the security of their account.


Decision

The fact that the database of all authorizations is located on the users’ device and decentralized authorization methods are a single entry point for all services, the problem of a device loss is not solved.

For developers, it’s necessary to make sure that:


So we receive the same usual functionality that we get in centralized services.

The user can choose different recovery methods:

Seed-phrase: The most secure, only the user knows it and is responsible for storing it, if a seed-phrase is lost, access is lost forever.

Google Account: Users trust google more than their devices. For example, when a user loses his phone, he is always able to restore everything from a Google account and never feels any inconvenience or security problems.

Apple Account: The same as Google Account.

Facebook Account: The same as Google Account.

Wechat Account: The same as Google Account.

Every selected option can be changed to another one at any time. In this way, the user can choose between full responsibility or delegation of responsibility for his security.

Another inconvenient factor surrounding decentralized authorization systems is that every action has to be confirmed on the device. If we want to leave a comment, we should generate the transaction that records this action on a blockchain. And this is different from the way centralized systems behave. YouTube users can immediately do this, without any additional actions.

Therefore, to emulate the functionality of a centralized system, a quota mechanism should be added to the decentralized system. Users will be asked to provide a quota for some actions at the moment of authorization.


For example, in the case of YouTube:

So, the user allows certain actions from a certain device, but all these quotas can be recalled in the future, because all information is stored in the blockchain.

We are focusing on the tools that will help to provide premiere user experience for developers and end-users.

For the Velas Ecosystem and its various services, DApps and products, we have designed Velas Account. This is a convenient way to execute on-chain operations and manage identity.

Through the Velas Account users will be able to access services, execute payments within them, send tokenized assets to other users, and login to applications seamlessly, by using biometric security on their phones. Our main goal is to make this as convenient as WeChat, Google Pay, and Apple Pay did.


.........

This is one of a series of articles outlining the complete package of Velas products on offer, and what the team has been working hard on over the past year. We’re covering everything from AIDPOS to Integrated Crypto Wallets and everything in between. You don’t want to miss it!
.........

(https://i.imgur.com/Q7AMD9w.png)
(https://i.imgur.com/4x2hvCL.png) (https://velas.com/?utm_source=jee_at)(https://i.imgur.com/aGfid15.png) (https://twitter.com/VelasBlockchain?utm_source=jee_at)(https://i.imgur.com/R68TW1Q.png) (https://www.facebook.com/velasblockchain?utm_source=jee_at)(https://i.imgur.com/jd6JBmW.png) (https://discord.com/invite/CTcKpPc?utm_source=jee_at)(https://i.imgur.com/AILSdXc.png) (https://medium.com/@VelasBlockchain)(https://i.imgur.com/Cz2l39O.png) (https://www.linkedin.com/company/velas-ag/?utm_source=jee_at)(https://i.imgur.com/M6TFpCe.png) (http://www.youtube.com/channel/UCZQNv-bdPKppg6akwWggmyQ?utm_source=jee_at)(https://i.imgur.com/OxNECAR.png) (https://www.instagram.com/velas.blockchain/?fbclid=IwAR1QHr8MMQ-wg-9OtYqOneGpIZD-5NgnyLheZqnVuniHuMTnxk_eVCL5CFg&utm_source=jee_at)(https://i.imgur.com/UaJYNmO.png) (https://t.me/velascommunity?utm_source=jee_at)
(https://i.imgur.com/Q7AMD9w.png)