Quantum Shield Auth is a lightweight, aesthetically pleasing verification widget inspired by modern cybersecurity standards. Moving away from traditional CAPTCHAs, it utilizes multi-layered Behavioral Analysis to distinguish humans from automated scripts.
- Biometric Slider: Analyzes cursor trajectory (Y-axis variance) and movement speed to block linear bot scripts.
- Environment Check: Deep scans for automation signatures such as
navigator.webdriverand hidden browser properties. - Dynamic Cell Input: Character-by-character input of a randomly generated word, verifying human typing rhythm (Keystroke Dynamics).
- Pressure Analysis: Measures "Hold-to-Verify" duration (ms) to eliminate instant programmatic clicks.
- UI Hardening: Strict prevention of text selection, copying, element dragging, and DevTools shortcuts (F12/Ctrl+U).
- HTML5 — Semantic structure.
- CSS3 — Custom properties and
cubic-bezieranimations. - JavaScript (ES6+) — Pure logic with zero external dependencies.
| Method | Metric | Target |
|---|---|---|
| Slider | Y-trajectory & Velocity | Linear scripts, Selenium |
| Checkbox | Network emulation delay | Headless browsers |
| Word Input | Keystroke Jitter ( |
Auto-fillers, Puppeteer |
| Smart Button | Hold duration threshold | Auto-clickers |
To make this widget production-ready, the client-side success must be verified by a secure backend. Simply receiving a verified: true flag is not enough.
Your backend should receive raw behavioral data and perform the following checks:
-
Entropy Analysis: Calculate the standard deviation of the mouse Y-coordinates. If
$SD \approx 0$ , the movement is synthetic. - Velocity Thresholds: Verify the time taken for each step. For example, if the 5-letter word was "typed" in less than 200ms, flag it as a bot.
- Sequence Check: Ensure steps were completed in the correct order (Slider -> Checkbox -> Typing -> Hold).
Prevent Replay Attacks (where a bot reuses a previous successful response):
- Challenge: On page load, the server generates a unique
nonce(UUID) and stores it in a short-lived cache (Redis). - Payload: The frontend sends the
nonceback along with the encrypted behavioral telemetry. - Signature: After validation, the server issues a signed JWT (JSON Web Token) containing a
claimthat allows the user to proceed to the next sensitive action (e.g., login or payment).
- Canvas Fingerprinting: Collect the browser's hardware rendering signature. If 50 different IP addresses share the same hardware fingerprint, they belong to the same bot farm.
- Datacenter Blocking: Check the user's IP against known lists of VPNs, Tor exit nodes, and AWS/GCP/Azure datacenter ranges.
- Clone the repository:
git clone [https://github.com/maxos-pl/quantum-shield-auth.git](https://github.com/maxos-pl/quantum-shield-auth.git)
- Deployment: Simply host the
index.html,style.css, andscript.json any web server. - Test Protection: Try to right-click, select text, or press
F12to see the UI hardening in action.
Distributed under the MIT License. See LICENSE for more information.
Developed with a focus on non-intrusive security and modern UX.