implementing-zero-knowledge-proof-for-authentication skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-zero-knowledge-proof-for-authentication/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-zero-knowledge-proof-for-authentication, or copy the skill folder into ~/.claude/skills/implementing-zero-knowledge-proof-for-authentication/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-zero-knowledge-proof-for-authentication/SKILL.md

SKILL.md (verbatim)

name: implementing-zero-knowledge-proof-for-authentication
description: Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret.
domain: cybersecurity
subdomain: cryptography
tags:
- cryptography
- zero-knowledge-proof
- authentication
- privacy
- zkp
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.DS-01
- PR.DS-02
- PR.DS-10
mitre_attack:
- T1600
- T1573
- T1553

Implementing Zero-Knowledge Proof for Authentication

Overview

Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private key) without revealing the secret itself. This skill implements the Schnorr identification protocol and a simplified ZKPP (Zero-Knowledge Password Proof) using the discrete logarithm problem, enabling authentication where the server never learns the user's password.

When to Use

  • When deploying or configuring implementing zero knowledge proof for authentication capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with cryptography concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Implement Schnorr's identification protocol for ZKP authentication
  • Build a non-interactive ZKP using Fiat-Shamir heuristic
  • Implement zero-knowledge password proof (ZKPP)
  • Demonstrate completeness, soundness, and zero-knowledge properties
  • Compare ZKP authentication with traditional password verification

Key Concepts

ZKP Properties

Property Description
Completeness Honest prover always convinces honest verifier
Soundness Dishonest prover cannot convince verifier (except negligible probability)
Zero-Knowledge Verifier learns nothing beyond the statement's truth

Schnorr Protocol

  1. Setup: Public generator g, prime p, q (order of g)
  2. Registration: Prover computes y = g^x mod p (public key from secret x)
  3. Commitment: Prover sends t = g^r mod p (random r)
  4. Challenge: Verifier sends random c
  5. Response: Prover sends s = r + c*x mod q
  6. Verify: Check g^s == t * y^c mod p

Security Considerations

  • Use cryptographically secure random number generators
  • Challenge must be unpredictable (from verifier's perspective)
  • For non-interactive proofs, use Fiat-Shamir with collision-resistant hash
  • ZKP alone does not provide forward secrecy; combine with TLS

Validation Criteria

  • Honest prover always verifies successfully (completeness)
  • Random response without secret does not verify (soundness)
  • Server never receives the secret value
  • Non-interactive proof is verifiable offline
  • Multiple authentications produce different transcripts
  • Protocol resists replay attacks

Other files in this skill

references/api-reference.md (verbatim)

API Reference: Zero-Knowledge Proof Authentication

hashlib (Python Standard Library)

PBKDF2 Key Derivation

import hashlib
key = hashlib.pbkdf2_hmac("sha256", password.encode(), salt.encode(), iterations)

SHA-256 Hashing (Fiat-Shamir Heuristic)

challenge = int(hashlib.sha256(data.encode()).hexdigest(), 16) % prime

secrets (Python Standard Library)

Function Description
secrets.randbelow(n) Cryptographically secure random int in [0, n)
secrets.token_hex(n) Random hex string of n bytes
secrets.token_bytes(n) Random bytes of length n

Schnorr Protocol Steps

Step Prover Verifier
Setup Private key x, public key y=g^x mod p Knows g, p, y
Commit Pick random k, send r=g^k mod p Receive r
Challenge - Send random c
Response Send s = k - c*x mod (p-1) Check g^s * y^c == r mod p

Fiat-Shamir Heuristic (Non-Interactive)

c = H(g || r || y)   # Challenge derived from hash
s = k - c * x mod (p-1)

ZKP Properties

Property Guarantee
Completeness Honest prover always convinces verifier
Soundness Dishonest prover fails with high probability
Zero-Knowledge Verifier learns nothing beyond validity

References

references/standards.md (verbatim)

Standards and References - Zero-Knowledge Proof for Authentication

Academic References

Schnorr Identification Protocol

  • Paper: "Efficient Signature Generation by Smart Cards" (Claus-Peter Schnorr, 1989)
  • Standard: ISO/IEC 9798-5 (Entity authentication using zero-knowledge techniques)

Fiat-Shamir Heuristic

  • Paper: "How To Prove Yourself" (Fiat, Shamir, 1986)
  • Description: Converts interactive ZKP to non-interactive using hash function

RFC 8235 - Schnorr Non-Interactive Zero-Knowledge Proof

RFC 5054 - SRP (Secure Remote Password)

Python Libraries

py-ecc

cryptography

references/workflows.md (verbatim)

Workflows - Zero-Knowledge Proof for Authentication

Workflow 1: Schnorr Interactive ZKP

Prover (knows secret x)              Verifier (knows y = g^x mod p)
      |                                      |
      |-- Commitment: t = g^r mod p -------->|
      |                                      |
      |<-- Challenge: c (random) ------------|
      |                                      |
      |-- Response: s = (r + c*x) mod q ---->|
      |                                      |
      |                              [Verify: g^s == t * y^c mod p]
      |                              [Accept or Reject]

Workflow 2: Non-Interactive ZKP (Fiat-Shamir)

Prover:
  1. Choose random r
  2. Compute t = g^r mod p
  3. Compute c = H(g || y || t)  (Fiat-Shamir)
  4. Compute s = (r + c*x) mod q
  5. Send proof (t, s) to verifier

Verifier:
  1. Compute c = H(g || y || t)
  2. Check g^s == t * y^c mod p

Workflow 3: Registration and Authentication

[Registration]:
  User --> [Choose password/secret x]
       --> [Compute y = g^x mod p]
       --> [Send y to server]
  Server --> [Store y (public key only)]

[Authentication]:
  User <--> Server: [Run Schnorr protocol]
  Server: [Verifies proof without learning x]
  Server: [Grants session token on success]

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.