If client doesn't have his private key, he won't be able to read his information even if he log in.
One additional verification procedure is required.
At the time of the login request, an encrypted email string using the user's private key is sent together.
ㄴㅡㅡ don't care. This is client-process
And server decrypts the cipher text with the public key and confirms it.