Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
@article{209279,
author = {Jayabandi Jersan and Prof. Dhavala Lalitha Bhaskari},
title = {An Adaptive Continuous Authentication Framework Using Zero-Knowledge Proofs for Session Hijacking Prevention},
journal = {International Journal of Innovative Research in Technology},
year = {2026},
volume = {13},
number = {5},
pages = {1120-1130},
issn = {2349-6002},
url = {https://ijirt.org/article?manuscript=209279},
abstract = {Conventional web authentication typically establishes trust during an initial login challenge and subsequently relies on a persistent session cookie or bearer authorization token until explicit expiry or manual logout. In decentralized Web3 ecosystems and cloud platforms, a compromised or stolen session credential may therefore be exploited repeatedly without requiring proof that the legitimate identity holder remains active at the endpoint.
The authors' previously published implementation combined client-side recursive zero-knowledge proofs (zk-SNARKs), freshness nonces, browser-native WebAssembly (Wasm), and read-only Layer-2 verification using a fixed 60-second heartbeat. This paper substantially extends that foundational paradigm by designing an adaptive, risk-aware continuous authentication architecture: routine cryptographic checks remain unobtrusive and computationally lightweight for stable sessions, whereas anomalous behavioral signals or network discrepancies dynamically shorten the re-verification interval, and critical security breaches prompt instantaneous verification or immediate session revocation.
Throughout this adaptive verification cycle, private witness credentials reside strictly within client volatile memory closures, guaranteeing zero exposure of raw credentials across network boundaries while preserving algebraic circuit soundness. This manuscript articulates the end-to-end framework architecture, formal risk-state policy formulations, threat vector mitigation models, an analytical comparison of scheduled computational proof counts, and a reproducible empirical evaluation methodology.
The resulting model bridges the historic trade-off between uncompromising Zero-Trust security and frictionless client performance, providing a scalable, gas-free identity layer for modern decentralized Web3 applications.},
keywords = {Adaptive authentication, continuous authentication, zero-knowledge proofs, session hijacking, risk-based authentication, zero-trust architecture, Groth16 zk-SNARKs, WebAssembly, Polygon Amoy, Web3 security.},
month = {October},
}
Submit your research paper and those of your network (friends, colleagues, or peers) through your IPN account, and receive 800 INR for each paper that gets published.
Join NowNational Conference on Sustainable Engineering and Management - 2024 Last Date: 15th March 2024
Submit inquiry