<?xml version="1.0" encoding="UTF-8"?>
<TEI xml:space="preserve" xmlns="http://www.tei-c.org/ns/1.0" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.tei-c.org/ns/1.0 https://raw.githubusercontent.com/kermitt2/grobid/master/grobid-home/schemas/xsd/Grobid.xsd"
 xmlns:xlink="http://www.w3.org/1999/xlink">
	<teiHeader xml:lang="en">
		<fileDesc>
			<titleStmt>
				<title level="a" type="main">PASSWORDLESS AUTHENTICATION USING MAGIC LINK TECHNOLOGY</title>
			</titleStmt>
			<publicationStmt>
				<publisher/>
				<availability status="unknown"><licence/></availability>
			</publicationStmt>
			<sourceDesc>
				<biblStruct>
					<analytic>
						<author>
							<persName><forename type="first">Iurii</forename><forename type="middle">S</forename><surname>Matiushin</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">Saint Petersburg State University</orgName>
								<address>
									<addrLine>7-9 Universitetskaya emb</addrLine>
									<postCode>199034</postCode>
									<settlement>Saint Petersburg</settlement>
									<country key="RU">Russia</country>
								</address>
							</affiliation>
							<affiliation key="aff0">
								<orgName type="institution">Saint Petersburg State University</orgName>
								<address>
									<addrLine>7-9 Universitetskaya emb</addrLine>
									<postCode>199034</postCode>
									<settlement>Saint Petersburg</settlement>
									<country key="RU">Russia</country>
								</address>
							</affiliation>
						</author>
						<author role="corresp">
							<persName><forename type="first">Vladimir</forename><forename type="middle">V</forename><surname>Korkhov</surname></persName>
							<email>av.korkhov@spbu.ru</email>
							<affiliation key="aff0">
								<orgName type="institution">Saint Petersburg State University</orgName>
								<address>
									<addrLine>7-9 Universitetskaya emb</addrLine>
									<postCode>199034</postCode>
									<settlement>Saint Petersburg</settlement>
									<country key="RU">Russia</country>
								</address>
							</affiliation>
							<affiliation key="aff0">
								<orgName type="institution">Saint Petersburg State University</orgName>
								<address>
									<addrLine>7-9 Universitetskaya emb</addrLine>
									<postCode>199034</postCode>
									<settlement>Saint Petersburg</settlement>
									<country key="RU">Russia</country>
								</address>
							</affiliation>
						</author>
						<title level="a" type="main">PASSWORDLESS AUTHENTICATION USING MAGIC LINK TECHNOLOGY</title>
					</analytic>
					<monogr>
						<imprint>
							<date/>
						</imprint>
					</monogr>
					<idno type="MD5">9478C393EE2A102132850F7ED5C57EAE</idno>
				</biblStruct>
			</sourceDesc>
		</fileDesc>
		<encodingDesc>
			<appInfo>
				<application version="0.7.2" ident="GROBID" when="2023-03-24T16:30+0000">
					<desc>GROBID - A machine learning software for extracting information from scholarly documents</desc>
					<ref target="https://github.com/kermitt2/grobid"/>
				</application>
			</appInfo>
		</encodingDesc>
		<profileDesc>
			<textClass>
				<keywords>
					<term>authentication</term>
					<term>passwordless</term>
					<term>magic link technology</term>
				</keywords>
			</textClass>
			<abstract>
<div xmlns="http://www.tei-c.org/ns/1.0"><p>Nowadays, the problem of identification and authentication on the Internet is more urgent than ever. There are several reasons for this: on the one hand, there are many Internet services that keep records of users and differentiate their access rights to certain resources; on the other hand, cybercriminals' attacks on web services have become much more frequent lately. At the same time, in many cases, the weak point of systems exposed to attacks is precisely the authentication system. Authentication methods based on the knowledge factor (e. g. password protection) are the most common and are applied almost everywhere. Their advantages are ease and low cost of implementation. On the other hand, such systems are often vulnerable to various kinds of attacks. It is estimated that up to 80% of successful hacker attacks (including attacks on the largest services with millions of users) succeeded precisely because of the weakness of the password protection system. This paper presents a solution to the problem of passwordless authentication, which can be applied in a number of online services and systems. In particular, we consider the magic link technology and present an authentication system implemented using Keycloak, an open-source software product that implements single sign-on technology. In the future, it is possible to further improve the system, in particular, using adaptive authentication, which allows switching between different authentication mechanisms depending on certain factors.</p></div>
			</abstract>
		</profileDesc>
	</teiHeader>
	<text xml:lang="en">
		<body>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="1.">Introduction</head><p>Modern distributed systems are becoming more and more complicated, with the number of their users constantly increasing; at the same time, attacks on such systems have become much more frequent as of late. This means that there is a need for security systems (including user authentication systems) that are, on the one hand, reliable and simple to use, and, on the other hand, meet the high security requirements necessary to protect the users' data from cyber threats <ref type="bibr" target="#b0">[1]</ref>. Another important aspect is making distributed systems convenient to use; this includes authentication systems.</p><p>In general, to access any protected resource, a user needs to go through three consecutive stages:</p><p> Identificationthe user must provide an identifier of some kind (username, e-mail address, phone number, etc.)  Authenticationthe user must prove their identity, i.e., provide some form of proof that they are who they claim to be  Authorizationif authentication is successful, the system grants the user access to the resource Our work is concerned with user authentication, as the most security-critical part of the entire access-granting pipeline.</p><p>Over the years, multiple various authentication methods have been created. They are generally classified according to the factor used to confirm the user's identity. In particular, the three main factors which are recognized nowadays are as follows:</p><p> Knowledge factor ("what you know"), when the user is assumed to possess a piece of secret information, such as a password or a PIN code  Possession factor ("what you have"), when the user must possess a unique physical device, such as a mobile phone or an electronic key  Inherence factor ("who you are") refers to methods based on biometrics, such as fingerprint scans, face recognition technology, etc. Today, knowledge-based authenticationin particular, password protectionis by far the most common authentication method. It has a number of advantages, such as being familiar to most if not all users and being cheap and easy to implement. That said, password-based systems also have several serious disadvantages. For one, there is an entire class of attacks based on obtaining or bruteforcing passwords, and it is estimated that up to 80% of successful hackings succeeded precisely because of a weakness in a password-based security system <ref type="bibr">[2]</ref>. Another problem is that password protection can be inconvenient for the end users. For example, based on the survey conducted by Keeper Security, 76% of mobile users store passwords by remembering them or writing them down, which often leads to passwords being forgotten or lost. As a result, 33% of users have to take 3 to 4 login attempts to remember a password, and 60% of users have had to reset a password in the 60 days preceding their participation in the survey <ref type="bibr">[3]</ref>.</p><p>In this paper, we consider passwordless authentication methods. Systems based on such methods have a number of advantagesease of use, protection against many common types of attacks, and the lack of need to create a large number of passwords. Passwordless authentication technologies are increasingly widespread, and are already in use by a number of large companies -Google, Medium, etc. In particular, the magic link technology is considered. Using it, the end user does not need to use a password to register or log in to the systemjust to enter an email address and follow the link sent by the authentication system. The link is unique, and authorization with its help is possible only for a specific user and only for a limited time. This approach not only greatly simplifies the process of registering new users and relieves them of the need to remember passwords, but also provides reliable protection against a number of attacks related to password theft or brute-force attacks.</p><p>We believe that the "traditional" password protection systems are often inadequate to the task of secure user authentication in distributed systems. For that reason, we have looked into several alternative authentication methods, and have implemented two such methods in practice.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2.">Alternative authentication methods: MFA, 2FA, passwordless authentication</head><p>One alternative that we have investigated is the use of multi-factor authentication (MFA).</p><p>As the name suggests, MFA means using several authentication methods, based on various authentication factors, to confirm a user's identity. The most common implementations of MFA tend to take the form of two-factor authentication (2FA), making user authentication a two-step process.</p><p>One possible implementation of the 2FA concept includes the use of one-time passwords (OTPs). In 2FA systems that use OTPs, the first step of the authentication process is usually similar to a "traditional" password-based authentication: a user enters a username and a password. During the second step, however, the user has to enter an OTP from their mobile device: the OTP is either sent to user's phone number as a text message or generated on the user's phone by a special application. Thus, such a system combines knowledge-based authentication (using passwords) with possessionbased authentication (a user having a mobile device which provides the OTPs).</p><p>2FA systems possess the advantage of having increased security compared to the "traditional" password-based authentication. For that reason, they are commonly used in contexts where security is crucial (for instance, bank transactions). On the other hand, such systems do not increase the user convenience of the authentication process; on the contrary, having to constantly use a mobile phone to log in can be tiring on everyday basis.</p><p>Another option is to forgo passwords entirely, and switch to passwordless authentication.</p><p>There are currently several ways to authenticate users without having to use passwords. One option, which has been gaining popularity lately, is to use the magic link technology.</p><p>In a system that uses that technology, a user only needs to enter an e-mail address to log in or sign up. An e-mail containing a unique link (which is referred to as "magic link") is then sent to the provided address, and the user can authenticate by simply clicking on the link. The magic link is, in a way, similar to an OTP, since it can be used to authenticate only a certain user and only for a short amount of time.</p><p>The magic link technology is easy and convenient for the users. There is no more need for them to remember a large number of passwords; furthermore, since multiple types of cyberattacks are based on obtaining passwords (as established earlier), a system using the technology is protected against many common attacks.</p><p>The magic link technology is already used by a number of companies, including Google, Medium, and others.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3.">Practical implementations</head><p>Currently, we have implemented a passwordless authentication system based on the magic link technology, as well as a 2FA system which uses time-based one-time passwords (TOTPs).</p><p>In order to implement these systems, we have used Keycloak. Keycloak is an open-source single sign-on (SSO) software product; SSO means that it allows a user to log in once and access several related services, instead of having to log in multiple times.</p><p>We have created a Keycloak magic link authentication module. The module allows the Keycloak administrator to set up e-mail-based passwordless authentication for a certain user, or a group of users.</p><p>The authentication flow can be described as follows <ref type="bibr" target="#b2">[4]</ref>:  The user starts the authentication process  The system requests the user's e-mail address, which the user provides  If the user doesn't exist within the system's database, a new user is created  The system then generates a unique token for the magic link and forms the magic link  The magic link URL is sent to the user's e-mail  The user clicks on the magic link and is redirected to the authentication page  The system checks if the magic link is valid; if it is, the user successfully logs in The authentication flow is shown in Figure <ref type="figure" target="#fig_0">1</ref>. The magic link's validity depends on several factors. Each link can only be used once; furthermore, there's a certain time limit, and the user cannot authenticate using an outdated magic link. Besides, the user must open the link in the same browser as the resource they are trying to gain access to.</p><p>In addition to implementing a passwordless authentication system, we have also created a 2FA system using TOTPs. To generate one-time passwords, we have used Google Authenticatora free mobile application developed by Google which allows the user to generate TOTPs on their mobile device. To set up authentication, a QR code is used; Authenticator scans it and starts generating OTPs, creating a new OTP after each set period of time <ref type="bibr" target="#b3">[5]</ref>.</p><p>User registration and using Google Authenticator are shown in Figure <ref type="figure" target="#fig_1">2</ref>. The authentication system that we have created is adaptive. This means that the system can either work as a regular password-based authentication system, or as a 2FA OTP-based system. For instance, if a user connects to the system from inside a company (that is to say, using a company IP), they only need to enter a password; however, if they connect from the outside, they need to complete both steps of the authentication process. Such a system balances user convenience with security, based on the assumption that the connections from within a company are more secure and do not necessarily need extra protection.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="4.">Conclusion and Future plans</head><p>We plan to continue working on passwordless authentication technology, investigating further avenues of research in this area.</p><p>One possible direction of research is the use of the WebAuthn standard. WebAuthn is a standard for web-based user authentication which was developed by W3C and FIDO Alliance as a part of the FIDO2 protocol. It allows the users to authenticate using a variety of methods, including biometrics (inherence-based authentication) or FIDO security keys (possession-based authentication) <ref type="bibr" target="#b4">[6]</ref>. As such, the development of that standard is an important step for the field of passwordless authentication.</p><p>Another option is to consider using decentralized identifiers (DIDs). DID is a new type of globally unique identifier, which has a number of essential characteristics: it is decentralized, meaning that there is no central issuing agency; it is persistent, not requiring the continued operation of any organization; importantly, it is cryptographically verifiable, so it is possible to prove control of the identifier using cryptographic methods <ref type="bibr" target="#b5">[7]</ref>. There is a currently developing authentication protocol based on the decentralized identifier technology called DID Auth. In this protocol, the user authenticates by proving that they are the owner of a certain DID. The authentication is based on the "challenge-response" method, which does not transmit a secret over the communication channel.</p></div><figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_0"><head>Figure 1 .</head><label>1</label><figDesc>Figure1. Magic link authentication flow<ref type="bibr" target="#b2">[4]</ref> </figDesc><graphic coords="4,86.38,70.90,422.48,150.25" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_1"><head>Figure 2 .</head><label>2</label><figDesc>Figure2. TOTP-based 2FA system user registration and authentication<ref type="bibr" target="#b3">[5]</ref> </figDesc><graphic coords="4,152.38,396.29,290.53,295.65" type="bitmap" /></figure>
			<note xmlns="http://www.tei-c.org/ns/1.0" place="foot" xml:id="foot_0">Proceedings of the 9th International Conference "Distributed Computing and Grid Technologies in Science andEducation" (GRID'2021), Dubna, Russia, July<ref type="bibr" target="#b3">[5]</ref><ref type="bibr" target="#b4">[6]</ref><ref type="bibr" target="#b5">[7]</ref>[8][9] 2021   </note>
		</body>
		<back>
			<div type="references">

				<listBibl>

<biblStruct xml:id="b0">
	<analytic>
		<title level="a" type="main">Implementation of Security in Distributed Systems -A Comparative Study</title>
		<author>
			<persName><forename type="first">Mohamed</forename><surname>Firdhous</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">International Journal of Computer Information Systems</title>
		<imprint>
			<biblScope unit="volume">2</biblScope>
			<biblScope unit="issue">2</biblScope>
			<date type="published" when="2011">2011</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b1">
	<monogr>
		<ptr target="https://www.keepersecurity.com/" />
		<title level="m">Consumer Mobile Security App Use</title>
				<imprint>
			<date type="published" when="2021-09-05">05.09.2021</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b2">
	<monogr>
		<title level="m" type="main">A guide to magic links: how they work and why you should use them</title>
		<ptr target="https://workos.com/blog/a-guide-to-magic-links" />
		<imprint>
			<date type="published" when="2021-09-05">05.09.2021</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b3">
	<monogr>
		<ptr target="https://auth0.com/blog/from-theory-to-practice-adding-two-factor-to-node-dot-js/" />
		<title level="m">From Theory to Practice: Adding Two-Factor Authentication to Node</title>
				<imprint>
			<date type="published" when="2021-09-05">05.09.2021</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b4">
	<monogr>
		<ptr target="https://www.w3.org/TR/webauthn-2/" />
		<title level="m">Web Authentication: An API for accessing Public Key Credentials Level 2</title>
				<imprint>
			<date type="published" when="2021-09-05">05.09.2021</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b5">
	<monogr>
		<ptr target="https://www.w3.org/TR/did-core/(accessed05." />
		<title level="m">Decentralized Identifiers</title>
				<imprint>
			<date type="published" when="2021-09">09.2021</date>
		</imprint>
	</monogr>
</biblStruct>

				</listBibl>
			</div>
		</back>
	</text>
</TEI>
