LuxurAI / Blog
← Back to all articles
Security & Cryptography August 2026 • 4 min read

Zero-Storage Passwordless Authentication: 384-Bit Single-Use Cryptographic Tokens

AS
Achyut Srivastava (14) & Shubham Dangi (15)
Founders & System Architects • LuxurAI (NexInova)

Every year, millions of user credentials leak from central password hashes. At LuxurAI, we engineered our security around a zero-storage principle: the backend physically stores zero user passwords.

The Architecture: Ephemeral 384-Bit Single-Use Tokens

Instead of storing credentials in a relational database:

  1. When a user requests login, an ephemeral 384-bit cryptographic entropy challenge is generated.
  2. The token is signed with HMAC-SHA384 using a rolling master key and dispatched over verified magic channels.
  3. Upon exchange, the session is created in an in-memory sliding window, and the single-use token is immediately burned.

Because no credentials exist on disk or in database tables, even a total database dump exposes zero user passwords.