Articles published on Online Authentication
Authors
Select Authors
Journals
Select Journals
Duration
Select Duration
81 Search results
Sort by Recency
- Research Article
1
- 10.1016/j.sasc.2026.200440
- Jun 1, 2026
- Systems and Soft Computing
- Aminou Halidou + 4 more
Enhanced OTP and facial recognition for e-learning authentication
- Research Article
- 10.11591/ijeecs.v39.i2.pp1121-1129
- Aug 1, 2025
- Indonesian Journal of Electrical Engineering and Computer Science
- Chihi Hasnae + 1 more
<p>Traditional CAPTCHA systems, designed to distinguish humans from bots, are increasingly ineffective due to advancements in artificial intelligence (AI), particularly deep learning and optical character recognition (OCR) technologies, which enable bots to bypass these systems. This paper proposes a new CAPTCHA authentication method that combines enhanced visual cryptography with traditional techniques to improve security. Visual cryptography divides information into visually distinct shares, reinforcing CAPTCHA’s defenses against automated attacks, especially those using deep learning. This approach not only strengthens security but also improves user experience by adjusting the time required to complete CAPTCHA challenges, addressing usability concerns associated with traditional systems. Overall, the proposed method offers a more secure, efficient, and user friendly solution for online authentication.</p>
- Research Article
1
- 10.21833/ijaas.2025.06.001
- Jun 19, 2025
- International Journal of ADVANCED AND APPLIED SCIENCES
- Randa Allafi + 1 more
This study examines the balance between usability and security in electronic online services by comparing the effectiveness and user experience of different authentication methods, including password-only authentication, multi-factor authentication (MFA), and biometric authentication. A mixed-methods approach was used to collect both quantitative and qualitative data through usability tests, surveys, semi-structured interviews, and case studies. The findings reveal a clear trade-off between usability and security. While MFA offers stronger protection, it poses usability challenges, especially for novice users who face more errors and take longer to complete tasks. In contrast, password-only authentication was faster and easier, but was seen as inadequate for protecting sensitive data. Biometric authentication emerged as the most preferred option, receiving high satisfaction ratings from both novice and experienced users due to its balance between ease of use and security. These results emphasize the importance of designing user-centered security solutions, such as increasing the adoption of biometric methods and simplifying MFA to enhance the user experience without sacrificing security. The study offers practical recommendations for developers and security professionals to create more accessible and secure online services.
- Research Article
- 10.1109/lcomm.2025.3564572
- Jun 1, 2025
- IEEE Communications Letters
- Lei Zhang + 4 more
In this letter, we propose a Vision Transformer-based Physical Layer Authentication (ViT-PLA) method for industrial wireless networks. To this end, Channel Frequency Response (CFR) samples are organized in dual-channel CFR images, which together with request positions encompass necessary information on the spatial-temporal correlation between CFR samples. Further, we design a novel Deep Neural Network (DNN) model consisting of a ViT and two feedforward neural networks to learn from the well-designed training samples. The implementation of the trained DNN model for online authentication is also discussed. Finally, the effectiveness and the generalizability of ViT-PLA are demonstrated on real industrial datasets.
- Research Article
1
- 10.3103/s0005105525700323
- Dec 1, 2024
- Automatic Documentation and Mathematical Linguistics
- A G Uymin + 1 more
With educational systems shifting to distance learning and the trend towards remote work growing, an urgent need has arisen to develop reliable biometric identification and authentication technologies to verify employees working remotely. Such technologies can provide a high degree of protection and usability, making their development and optimization extremely important. The issue is that accuracy and efficiency of mouse gesture recognition systems need to be improved without any specialized devices used and in the shortest possible time. This requires efficient preprocessing of such gestures to simplify their trajectories while preserving their key features. The Douglas–Peucker algorithm is proposed to be used for preliminary processing of mouse gesture trajectory data. This algorithm allows significantly reducing the number of points in the trajectories, simplifying them while preserving the principal shape of the gestures. The data with simplified trajectories are then used to train neural networks. The experimental part of the work showed that, when applied, the Douglas–Peucker algorithm allows for a 60% reduction in the number of points on the trajectories, increasing the gesture recognition accuracy from 70 to 82%. Such data simplification contributes to speeding up the neural networks' training process and improving their operational efficiency. The study confirmed the efficiency of using the Douglas–Peucker algorithm for preliminary data processing in mouse gesture recognition problems. The results can be applied to develop more intuitive and adaptive user interfaces. In addition, directions for further research, including optimization of the algorithm’s parameters for different types of gestures and exploring the possibility of combining it with other machine learning methods, are proposed.
- Research Article
- 10.3233/shti241036
- Nov 18, 2024
- Studies in health technology and informatics
- Helen Petrie + 1 more
There is a growing body of research on the problems older and disabled people face with authentication systems and a range of solutions have been developed. However, this research has not been integrated across user groups and solutions usually only target one or two groups. This research has attempted to integrate the empirical research findings across studies conducted with people with visual, physical, and intellectual disabilities, people dyslexia and older people. It proposes an initial set of 15 recommendations for the universal design of authentication systems. Four recommendations are about authentication systems in general, six about password authentication, two about CAPTCHAs and three about biometric authentication. 40% of the recommendations address problems experienced by at least two different user groups and over 25% address problems experienced by three groups. However, much further work is needed to validate and refine the recommendations and integrate them into a universal design approach.
- Research Article
2
- 10.62754/joe.v3i7.4608
- Nov 4, 2024
- Journal of Ecohumanism
- Fina Nazran + 3 more
This paper examines the legal framework and challenges notaries face in adopting technology-based systems for document validation in Indonesia, with a comparative analysis involving the United States, the Netherlands, and Australia. Indonesia's legal framework, particularly Law No. 2 of 2014 on the Office of Notary, has yet to fully accommodate electronic signatures and remote notarization. The requirement for in-person meetings for authenticating notarial acts creates a regulatory barrier to implementing cyber notary services. Furthermore, Indonesian notaries face limited access to essential data systems, such as Dukcapil (Civil Registration Directorate) and BPN (National Land Agency), complicating the verification of personal identity and property documents. In contrast, the United States has adopted e-notary systems, using blockchain technology to ensure data integrity and mitigate fraud risks. The Netherlands provides an integrated platform, allowing notaries to validate documents remotely by accessing national databases in real time. Meanwhile, Australia has implemented a Digital Identity Program to facilitate efficient online authentication of documents. These innovations demonstrate how interoperability, regulatory flexibility, and digital literacy can enhance notary services and legal certainty. This paper proposes regulatory reforms in Indonesia, including revising existing laws to support remote notarization and electronic signatures. Second, developing integrated data platforms for real-time access. Third, providing training programs for notaries to adopt new technologies and ensure data security. By aligning Indonesia’s legal framework with international best practices, cyber notary services can enhance efficiency, security, and legal protection for both notaries and the public, meeting the demands of the digital era.Comparison
- Research Article
- 10.26907/1562-5419-2024-27-4-679-694
- Sep 6, 2024
- Russian Digital Libraries Journal
- Anton Grigorievich Uymin + 1 more
In today's world, digital technologies are penetrating all aspects of human activity, including education and labor. Since 2019, when, in response to global challenges, the world's educational systems have actively started to shift to distance learning, there has been an urgent need to develop and implement reliable identification and authentication technologies. These technologies are necessary to ensure the authenticity of work and protection from falsification of academic achievements, especially in the context of higher education in accordance with the group of specialties and directions (USGS) 10.00.00 - Information Security, where laboratory and practical work play a key role in the educational process. The problem lies in the need to optimize the flow of incoming data, which, first, can affect the retraining of the neural network core of the recognition system, and second, impose excessive requirements on the network's bandwidth. To solve this problem, efficient preprocessing of gesture data is required to simplify their trajectories while preserving the key features of the gestures. This article proposes the use of the Douglas–Peucker algorithm for preliminary processing of mouse gesture trajectory data. This algorithm significantly reduces the number of points in the trajectories, simplifying them while preserving the main shape of the gestures. The data with simplified trajectories are then used to train neural networks. The experimental part of the work showed that the application of the Douglas–Peucker algorithm allows for a 60% reduction in the number of points in the trajectories, leading to an increase in gesture recognition accuracy from 70% to 82%. Such data simplification contributes to speeding up the neural networks' training process and improving their operational efficiency. The study confirmed the effectiveness of using the Douglas–Peucker algorithm for preliminary data processing in mouse gesture recognition tasks. The article suggests directions for further research, including the optimization of the algorithm's parameters for different types of gestures and exploring the possibility of combining it with other machine learning methods. The obtained results can be applied to developing more intuitive and adaptive user interfaces.
- Research Article
10
- 10.1016/j.jpdc.2024.104946
- Jul 3, 2024
- Journal of Parallel and Distributed Computing
- Khalid Javeed + 2 more
GMC-crypto: Low latency implementation of ECC point multiplication for generic Montgomery curves over GF(p)
- Research Article
- 10.56279/orseaj.v14i1.6
- Jun 18, 2024
- ORSEA JOURNAL
- Ayubu Alfani Mbwambo + 2 more
This study looks at the evolution of FinTech from a disruptive force to acomplementary element within the financial landscape. Drawing on disruptiveinnovation theory and financial intermediation theory, this study takes a holisticapproach to uncover the mechanisms driving this change. Data was collectedusing a structured questionnaire distributed to 162 IT employees of financialinstitutions in Tanzania. The data was analyzed using structural equationmodeling with Smart PLS. The results show the positive influence of thescalability of FinTech systems and online authentication on financial inclusionand emphasize their central role in expanding access to financial services. Theeffectiveness of online authentication in promoting financial inclusion isparticularly noteworthy. However, the results show that product substitutabilityhas a negligible influence on financial inclusion, pointing to the need for astrategic reorientation of resource allocation. These findings provide industrypractitioners with valuable strategies to navigate the complex intersection ofFinTech and traditional banking. This study contributes to the theoreticaldiscourse by presenting a unique model that integrates disruptive innovationtheory and financial intermediation theory. It argues for concerted efforts to useFinTech as a catalyst for promoting financial inclusion and draws attention toits potential as a powerful enabler for inclusive financial systems. Keywords: Financial inclusion; financial technology; FinTech; Disruptive Innovation;Financial Intermediation.
- Research Article
- 10.56279/orseaj.14.1.6512
- Jun 18, 2024
- ORSEA JOURNAL
- Ayubu Alfani Mbwambo + 2 more
This study looks at the evolution of FinTech from a disruptive force to acomplementary element within the financial landscape. Drawing on disruptiveinnovation theory and financial intermediation theory, this study takes a holisticapproach to uncover the mechanisms driving this change. Data was collectedusing a structured questionnaire distributed to 162 IT employees of financialinstitutions in Tanzania. The data was analyzed using structural equationmodeling with Smart PLS. The results show the positive influence of thescalability of FinTech systems and online authentication on financial inclusionand emphasize their central role in expanding access to financial services. Theeffectiveness of online authentication in promoting financial inclusion isparticularly noteworthy. However, the results show that product substitutabilityhas a negligible influence on financial inclusion, pointing to the need for astrategic reorientation of resource allocation. These findings provide industrypractitioners with valuable strategies to navigate the complex intersection ofFinTech and traditional banking. This study contributes to the theoreticaldiscourse by presenting a unique model that integrates disruptive innovationtheory and financial intermediation theory. It argues for concerted efforts to useFinTech as a catalyst for promoting financial inclusion and draws attention toits potential as a powerful enabler for inclusive financial systems. Keywords: Financial inclusion; financial technology; FinTech; Disruptive Innovation;Financial Intermediation.
- Research Article
- 10.55041/ijsrem34662
- May 25, 2024
- INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
- Bhavana R M
Fast Identity Online 2 (FIDO2) emerges as a transformative solution to the vulnerabilities inherent in traditional password-based authentication methods. Leveraging public key cryptography and authenticators, it establishes a passwordless authentication paradigm, extending its relevance beyond web applications to diverse realms such as online payments and government services. This paper explores FIDO2's emphasis on a seamless user experience while bolstering security measures through innovative credential management techniques. The acceptance of FIDO2 on major browsers ensures its usability on mobile devices, with most modern devices equipped to support FIDO2 authentication, thus expanding its reach and applicability. Additionally, its adoption by major tech companies and standards bodies underscores its credibility and potential for widespread adoption. However, challenges remain, including overcoming legacy systems, addressing compatibility issues, and ensuring user education. Despite these challenges, FIDO2 represents a significant advancement in online authentication, offering strong security, usability, and privacy features, positioning it as a key enabler of the passwordless authentication paradigm. Keywords: Public key cryptosystem, challenge, relying party, web browser and web authentication.
- Research Article
8
- 10.62441/nano-ntp.vi.4706
- Apr 15, 2024
- Nanotechnology Perceptions
- Medha Gupta + 4 more
Today, in the accelerating pace of cyber threats, new approaches and adaptive protection are required, specifically on risk analysis and fraud. Therefore, Adversarial Machine Learning with Artificial Intelligence provides a complete framework for fast-in-time cybersecurity threats assessment and advanced fraud detection capability. AML techniques would be critical for representing potential online attacks, ensuring AI-enabled defense systems are stronger and more resilient, and ultimately mitigating an adversarial attack. The fact that AML has both defensive and attacking uses shows that it's the requirement for developing models resistant to adversaries that is being made with a proper defense against emerging cyber threats. It introduces an adaptive risk identification framework, using predictive modeling, machine learning algorithms, and real-time data analysis for detecting, ranking, and mitigating risks dynamically. This is the method that keeps security protocols one step ahead of possible threats-they make this happen through a continuous evolution in their capacities to keep up with the speed of the digital world. Examples of using AI as one of the impressive tools in analyzing and owning huge datasets to detect anomalies and discover patterns of fraudulent behavior are, among others, the use of AI to do online fraud detection. It shows practical use of AI for fraud detection, from secure online authentication to preventing financial fraud. Evidence from real life helps demonstrate how AI-driven solutions can improve current risk assessment methodologies and fraud detection systems in response to increasingly complex cyber threats. The results provide a holistic view of how AML and AI techniques strengthen cyber defenses while contributing to effective cybersecurity practices. The demand for AI to take up mobility in AML has, however, begun to be very pertinent regarding the safety of digital assets, integrity of online systems, and the walls of defense erected against increasingly sophisticated cyber threats in a highly connected digital terrain. This study reflects the critical adoption of intelligent and adaptive solutions in meeting the demands posed by modern cybersecurity.
- Research Article
14
- 10.1016/j.cose.2024.103771
- Feb 23, 2024
- Computers & Security
- Francesco Buccafurri + 3 more
Security policies of authentication systems are a crucial factor in mitigating the risk of impersonation, which is often the first stage of advanced persistent threats. Online authentication systems may often interact with each other, due to various mechanisms, such as account recovery or federated authentication. This leads to an implicit extension of the security policies of an authentication system with policies over which the system has no control. As a result, an authentication system that adopts very strong security policies can be unexpectedly weak. This paper deals with the above problem, which affects most real-world online authentication systems. The paper proposes a theoretical framework that formalizes authentication policies and interactions among authentication systems, together with a protocol that prevents, whenever an interaction is established or updated, the security issues described above. An SSI-based implementation of the proposed protocol is presented as well.
- Research Article
12
- 10.1109/jiot.2023.3299465
- Dec 15, 2023
- IEEE Internet of Things Journal
- Saiyed Umer + 4 more
A multimodal biometric recognition system on Internet of Things (IoT) with Blockchain environments has been proposed in this article. This system distributes a decentralized biometric authentication process mechanism and improves security in the IoT environment. The implementation of this system consists of five components: 1) image preprocessing; 2) feature representation; 3) cancelable biometrics; 4) classification; and 5) encryption–decryption of multimodal biometrics templates. A region of interest is segmented from each biometric trait during image preprocessing. Then, a discriminant feature extraction technique has been employed for feature computation. A cancellable biometric system (CBS) is introduced to secure and preserve the original biometric features from external hazards and misuse. The extracted cancelable features undergo classification to perform the subjects’ authentication. Then, a method of encryption–decryption of templates is performed to handle the various online authentication attacks and improve IoT-enabled authentication. Finally, the recognition scores due to iris, periocular, palmprint, and face biometrics are fused to increase the performance of the proposed IoT-enabled multimodal biometric system. The proposed system obtains identification performance 99.92%, 100% for CASIA-V4-distance (CASIA-DIST), UBIRIS-v2 iris, 100% for periocular (CASIA-DIST, UBIRIS-v2), 100% for Bosphorus palmprint, and 100% for FERET face databases using 30-D cancelable features that show the superiority of the proposed system as compared with state-of-the-art methods.
- Research Article
6
- 10.18523/2617-2607.2023.11.64-76
- Oct 26, 2023
- NaUKMA Research Papers. Law
- Daria Bulgakova + 1 more
The legal identity of individuals is critical in digital ecosystems, and biometric systems play a vital role in verifying identities throughout their lives. However, these systems also pose significant risks and require responsible use. The European Union has established a digital strategy to create a trusted and secure digital identity, setting a global standard for technological development in identification. In line with the General Data Protection Regulation Article 9(1), member countries must justify any exceptions to the rule provided. France has taken a leading role in using unique identification legally, implementing digitally processed attributes such as facial recognition through the Alicem application on smartphones to identify individuals in a digital environment, and improving e-services uniquely. Specifically, the article analyses the General Data Protection Regulation Article 9, paragraph 1, and the exceptional conditions outlined in paragraph 2 (a) (g) along with scrutinized legislation in France of Decree n°2019-452 of 13 May 2019, which authorized the use of unique identification known as ‘Certified Online Authentication on Mobile.’ The research recommends that EU member countries taking approaches to introduce GDPR Article 9 into national legislation should consider their citizens’ specific needs and concerns while aligning with the European Union law because it is critical to balance the benefits of biometric systems with the risks posed to personal data protection, ensuring that their responsible use contributes to a secure and trustworthy digital ecosystem.
- Research Article
- 10.32523/2616-6887/2023-143-2-232-240
- Jan 1, 2023
- BULLETIN of the L.N. Gumilyov Eurasian National University.Political Science. Regional Studies. Oriental Studies. Turkology Series.
- N.Ye Khamitova + 1 more
This article examines South Korea’s main policy related to online authentication and data access control, having major changes and the reasons behind them. It analyzes the driving forces of this policy such as Korea’s ICT policy, cybersecurity incidents, and cybersecurity policy. It presents the features of the development of the online authentication process and touches upon the problems of data access control. The article considers digital new projects of South Korea aimed at the development of a digital society. South Korea’s digital environment is one of the most advanced ones in the world. The digitalization of society has intensified even more with the division of society into before and after the Covid-19 pandemic, which showed the level of development of each state in the field of digital technology. National approaches and cybersecurity have become an element of the successful promotion of South Korea’s digitalization policy.In conclusion, the importance of developing the digital environment according to a certain country-specific model is outlined, and it is considered as an important modern tool in the process of implementing the development of a unique digital environment
- Research Article
10
- 10.1109/tifs.2022.3214729
- Jan 1, 2023
- IEEE Transactions on Information Forensics and Security
- Wenting Li + 2 more
Password-only authentication is one of the most popular secure mechanisms for real-world online applications. But it easily suffers from a practical threat - password leakage, incurred by external and internal attackers. The external attacker may compromise the password file stored on the authentication server, and the insider may deliberately steal the passwords or inadvertently leak the passwords. So far, there are two main techniques to address the leakage: Augmented password-authentication key exchange (aPAKE) against insiders and honeyword technique for external attackers. But none of them can resist both attacks. To fill the gap, we propose the notion of <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">honey PAKE (HPAKE)</i> that allows the authentication server to detect the password leakage and achieve the security beyond the traditional bound of aPAKE. Further, we build an HPAKE construction on the top of the honeyword mechanism, honey encryption, and OPAQUE which is a standardized aPAKE. We formally analyze the security of our design, achieving the insider resistance and the password breach detection. We implement our design and deploy it in the real environment. The experimental results show that our protocol only costs 71.27 ms for one complete run, within 20.67 ms on computation and 50.6 ms on communication. This means our design is secure and practical for real-world applications.
- Research Article
10
- 10.56553/popets-2022-0129
- Oct 1, 2022
- Proceedings on Privacy Enhancing Technologies
- Michal Kepkowski + 3 more
This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by the FIDO industry alliance for secure token online authentication. It complements the W3C WebAuthn specification by providing means to use a USB token or other authenticator (which holds the secret authenticating material and implements FIDO protocols) as a second factor during the authentication process. From a cryptographic perspective, the protocol is a simple challenge-response where the elliptic curve digital signature algorithm is used to sign challenges. To protect the privacy of the user the token uses unique key pairs per service. To accommodate for small memory, tokens use various techniques that make use of a special parameter called a key handle sent by the service to the token with which the token can securely produce an authentication key (through generation or decryption). We identify and analyse a vulnerability in the way the processing of key handles is implemented that allows attackers to remotely link user accounts on multiple services. We show that for vulnerable authenticators there is a difference between the time it takes to process a key handle for a different service but correct authenticator, and for a different authenticator but correct service. This difference can be used to perform a timing attack allowing an adversary to link user’s accounts across services. We present several real world examples of adversaries that are in a position to execute our attack and can benefit from linking accounts. We found that two of the eight hardware authenticators we tested were vulnerable despite FIDO level 1 certification, indicating a not insignificant problem. This vulnerability cannot be easily mitigated on authenticators because, for security reasons, they usually do not allow firmware updates. In addition, we show that due to the way existing browsers implement the WebAuthn standard, the attack can be executed remotely. However, we discuss countermeasures that can be implemented by browser providers to mitigate the remote form of the attack.
- Research Article
33
- 10.1016/j.pmcj.2022.101683
- Aug 17, 2022
- Pervasive and Mobile Computing
- Neyire Deniz Sarier
Privacy Preserving Biometric Authentication on the blockchain for smart healthcare