Implementation a Passwordless and Multi Factor Authentication (MFA) Mechanism for Enhancing Login Security in Android Applications | IEEE Conference Publication | IEEE Xplore

Implementation a Passwordless and Multi Factor Authentication (MFA) Mechanism for Enhancing Login Security in Android Applications


Abstract:

In keeping up with technological advancements, the demand for services has also increased significantly. These services typically require authentication using usernames a...Show More

Abstract:

In keeping up with technological advancements, the demand for services has also increased significantly. These services typically require authentication using usernames and passwords. However, the use of passwords presents several significant issues. Apart from being vulnerable to brute force attacks, dictionary attacks, and shoulder surfing, many users also tend to be careless in managing their passwords. This issue is further exacerbated by the habit of using the same password across various applications, infrequent password changes, and a tendency to use easily guessable passwords. Despite password management being recommended, the reality is that many password management services are not optimal in securing user data. To address these problems, this research has designed and developed a passwordless authentication system based on Android, referred to as the passwordless system. This system utilizes the Flutter framework for its implementation. The passwordless system is implemented using client certificates, along with the addition of Multi-Factor Authentication (MFA) features involving usernames, OTP codes, and fingerprint scanning. The development of this passwordless system was carried out using the Design Science Research approach and the Waterfall Life Cycle model. The process encompassed various testing stages, including unit testing, integration testing, system testing, and User Acceptance Testing (UAT). UAT involved 100 respondents from the students of the Polytechnic of Cyber Security and State Intelligence. The testing results demonstrated that the passwordless system successfully addressed the identified issues in this research. UAT also indicated that the system is user-friendly, with a 92.22% agreement rate indicating "Strongly Agree." In this context, the passwordless system holds an advantage over password-based systems. Therefore, this research has successfully designed and implemented an Android-based passwordless system using the Flutter framew...
Date of Conference: 07-08 November 2023
Date Added to IEEE Xplore: 14 December 2023
ISBN Information:

ISSN Information:

Conference Location: Jakarta Selatan, Indonesia

Contact IEEE to Subscribe

References

References is not available for this document.