A Novel Typeless Multifactor Authentication Scheme to Prevent Advanced Persistent Threats
Nowadays, millions of users rely on various types of two-factor authentication (2FA) to secure their accounts in Web 3.0 decentralized and sensitive applications (hereafter referred to as (D)Apps), such as cryptocurrency wallets. Standard user-to-device (U2D) authentication schemes aim to prevent account compromise by requiring one or more verifiable factors. Technically, these credentials can be stolen under certain adversarial scenarios via a device (e.g., an advanced persistent threat enabled by an unpatched vulnerability). To address this issue, this paper proposes a novel explainable Artificial Intelligence (AI)-based dynamic U2D scheme, named Web3U2D, that combines a broad-learning hint generation algorithm based on a bidirectional long short-term memory approach with an attention mechanism. Our proposed scheme enables users to set and memorize multiple secret factors, such as a 4-digit hidden PIN (HPIN) and a 4-symbolic hidden password (HP), during the registration phase. Then, considering an AI-generated hint item, the user must remember two hidden credentials and find two one-time-valid combinations from four selective lists of newly randomized entryways, without typing them at each authentication attempt, thereby preventing the exposure of users’ original combinations. Our results confirm that the Web3U2D approach offers superior performance compared to state-of-the-art schemes based on standard evaluation metrics.