Trust: A Web-Based Examination Platform Unifying FIDO2 Password-less Authentication and Lightweight Snapshot-Based Proctoring
Abstract
Remote online examinations struggle to balance identity verification and assessment integrity. Passwords remain weak and shareable, while continuous video proctoring compromises privacy and consumes high bandwidth. This thesis introduces Trust, an open-source, web-based platform unifying passwordless identity binding with lightweight, multimodal integrity monitoring. Trust rests on four architectural pillars: FIDO2/WebAuthn authentication, tri-modal proctoring, deterministic enforcement, and privacy-respecting data management. Authentication eliminates shared secrets utilizing admin-issued single-use registration tokens and server-side sign_count replay protection. The proctoring fabric fuses a visual axis processing randomized snapshots, an audio axis utilizing local-only voice activity detection, and a behavioural axis tracking edge-triggered DOM events. A unified three-strike policy evaluates submissions securely on the server, while biometric buffers remain strictly transient to retain only confirmed violation evidence. Trust is engineered with a Django/Celery backend (PostgreSQL/Redis) and a Next.js/React client executing in-tab inference. It was implemented under local Docker Compose and subsequently deployed to a cloud provider, though quantitative benchmarks against continuous-video baselines remain pending. Trust proposes an integrated design for passwordless authentication, snapshot-based proctoring, and tamper-resistant enforcement without continuous video, serving as a foundational prototype for future empirical validation.