MATHEMATICAL CORRECTNESS OF THE AUTHENTICATION PROCESS BASED ON A FINITE-STATE MACHINE
Keywords:
authentication, deterministic finite automaton, DFA, multifactor authentication, biometrics, PIN code, Shannon entropy, formal verification, ChaCha 20- Poly 1305, session keyAbstract
This paper examines a mathematical model of multifactor authentication in which the factor verification sequence is controlled by a deterministic finite automaton. The baseline scenario is a two-factor "biometric verification → PIN code" scheme, supplemented by a reset or session end event. A state set, an input alphabet, a transition function, and initial and accepting states are formally defined. Based on this, the determinism of the automaton, the reachability of the accepting state, the absence of deadlocks, and the impossibility of successfully completing a minimal session if the established factor order is violated are proven. To analyze the automaton's trajectories, a probabilistic description of state visit frequencies and normalized Shannon entropy are introduced, allowing for a quantitative characterization of the uniformity of the transition distribution. It is shown that the normalized entropy lies between 0 and 1 and reaches a maximum for a uniform state probability distribution. Additionally, the session success rate, the wireless channel stability indicator, and the integral stability metric are considered. The boundedness of the integral metric is proven on the interval from 0 to 1 for non-negative weights whose sum is equal to one. It is shown that a finite-state machine can be used as a formal mechanism for accessing session keys without replacing them with cryptographic primitives. The proposed model is designed for mobile and embedded systems with limited computing resources.
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.