The key contributions of this work are summarised as
follows:
• A working ZKP-based multi-factor system. We im-
plement the interactive Schnorr protocol end to end and
compose it with server-side face matching and an email
possession factor across five selectable modes, with an
ESP32-CAM as the physical authentication endpoint.
• A credential store with no recoverable secret. The
verifier persists only Y = gx mod p. Section III states
precisely what this protects against and, equally impor-
tantly, what it does not: a short PIN remains subject to
offline enumeration.
• An operating-point finding. Benchmark evaluation
shows impostor similarity never exceeding 0.167 while
the deployed threshold is 0.65, so the threshold can be
lowered substantially without admitting a single false ac-
ceptance. This is a correction to our own design obtained
by measurement rather than a property we designed in.
