- use random challenge for registration and authentication ceremonies - introduce nonce into the request payload