Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (102)

Search Parameters:
Keywords = multifactor authentication

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
32 pages, 2754 KB  
Systematic Review
Security Challenges and Mitigation Strategies in IoT-Enabled Video Surveillance Systems: A Systematic Review
by Josphat Moyo, Brett Van Niekerk, Richard C. Millham and Halleluyah Oluwatobi Aworinde
J. Sens. Actuator Netw. 2026, 15(4), 61; https://doi.org/10.3390/jsan15040061 - 31 Jul 2026
Viewed by 738
Abstract
The rapid deployment of Internet of Things (IoT)-enabled video surveillance systems has expanded the capabilities of real-time monitoring in smart cities, healthcare facilities, industrial environments and critical infrastructure. However, integrating resource-constrained cameras, heterogeneous communication protocols, edge/cloud analytics, and sensitive video data creates a [...] Read more.
The rapid deployment of Internet of Things (IoT)-enabled video surveillance systems has expanded the capabilities of real-time monitoring in smart cities, healthcare facilities, industrial environments and critical infrastructure. However, integrating resource-constrained cameras, heterogeneous communication protocols, edge/cloud analytics, and sensitive video data creates a complex cybersecurity landscape. This systematic review synthesizes recent evidence on security challenges and mitigation strategies in IoT-enabled video surveillance systems. Following the PRISMA 2020 guidelines, four bibliographic databases (Scopus, IEEE Xplore, Web of Science, and Google Scholar) were searched for peer-reviewed journal articles and conference papers published between January 2021 and July 2025. After duplicate removal, title/abstract screening, full-text assessment, and quality appraisal, 21 studies were included for qualitative synthesis. The findings show that vulnerabilities occur across three interdependent architectural layers: device/perception, network/communication, and application/cloud. The frequently reported weaknesses were default credentials, insecure firmware, unencrypted video streams, weak protocol configuration, metadata leakage, and inadequate cloud access control. Existing mitigation strategies, including multi-factor authentication, role-based access control, TLS/DTLS, lightweight encryption, intrusion detection systems, and secure boot, provide partial protection but remain constrained by latency, computational overhead, energy consumption, scalability, cost and legacy device compatibility. This review further identifies a persistent research–practice gap: only a small subset of studies provides evidence of real-world deployments, while most solutions remain evaluated in simulations, testbeds, or conceptual frameworks. This review contributes a domain-specific taxonomy of IoT video surveillance security, a comparative evaluation of mitigation strategies using technical, operational, and economic criteria, and deployment-oriented recommendations for smart city, industrial, healthcare, residential, and critical infrastructure settings. The study highlights the need for cross-layer security architectures, lightweight and post-quantum-ready cryptography, privacy preservation, edge AI, federated learning, zero-trust access control, and standardized security baselines. Full article
(This article belongs to the Special Issue IoT and Networking Technologies for Smart Mobile Systems)
Show Figures

Figure 1

20 pages, 7491 KB  
Article
Non-Targeted Metabolomics Reveals the Metabolic Differentiation of Rice from Adjacent Small-Scale Producing Areas and Its Response to Climatic and Soil Factors
by Xianxin Wu, Zeting Li, Tianshu Peng, Lina Li, Qiujun Lin, Guang Li, Chunjing Guo, Qingchuan Liu and Jianzhong Wang
Foods 2026, 15(14), 2499; https://doi.org/10.3390/foods15142499 - 15 Jul 2026
Viewed by 337
Abstract
Geographical traceability of rice is critical for authenticity identification and quality control, yet it poses considerable challenges for tracing origins in adjacent small-scale producing areas. To explore the causes of metabolic differences and geographical traceability potential of rice from adjacent small-scale producing areas, [...] Read more.
Geographical traceability of rice is critical for authenticity identification and quality control, yet it poses considerable challenges for tracing origins in adjacent small-scale producing areas. To explore the causes of metabolic differences and geographical traceability potential of rice from adjacent small-scale producing areas, non-targeted metabolomics combined with multivariate statistical analysis was employed to systematically investigate the metabolic profiles of rice from Panjin (PJ), Donggang (DG) and Yingkou (YK) in Liaoning Province. The characteristic metabolic markers for each producing area were screened, and the effects of climatic and soil factors as well as their interactive effects on grain metabolite composition were elucidated. The results showed that the partial least squares-discriminant analysis (PLS-DA) model established based on differential metabolites achieved acceptable discrimination among rice samples from the three regions. With variable importance in projection (VIP) > 2.0 as the screening threshold, the core characteristic markers of each producing area were determined: PJ is LPC 17:2, LPA 18:3, D-(+)-Arabitol, DG is 2′-Deoxyadenosine, LDGTS 18:2, and YK is LPE 17:2; the markers are mainly primary metabolites, including lipids, sugar alcohols and nucleotides. Sunshine duration, air humidity, wind conditions and soil layer temperature were highly correlated climatic drivers responsible for metabolic differentiation, and characteristic metabolic markers from different producing areas exhibited distinct meteorological response patterns. Soil physicochemical properties and mineral elements significantly affected the differential accumulation of metabolites, among which soil Sr element and organic matter exhibited crucial indicative significance for metabolic variation of rice in adjacent regions. Multi-factor interaction analysis verified significant synergistic coupling effects between regional climate and soil environment. Meteorological factors, including sunshine, wind and soil temperature, together with soil chemical factors involving organic matter, pH, Sr, K and Ca, were identified as core driving factors for the spatial differentiation of region-specific rice metabolites. The present study provides theoretical support at the metabolic level for the construction of a small-scale rice geographical traceability system and the mechanism research on the regional quality formation of rice. Full article
Show Figures

Figure 1

37 pages, 2807 KB  
Article
Enhancing CIA Triad—Confidentiality, Integrity and Availability in Educational Information Systems Through Next-Generation ISO/IEC 27001:2022-Aligned Security Model
by Dejan Vasović, Goran Janaćković, Žarko Vranjanac, Srećko Stamenković and Bojan Vasović
Appl. Sci. 2026, 16(12), 6260; https://doi.org/10.3390/app16126260 - 22 Jun 2026
Viewed by 825
Abstract
Educational information systems have evolved into highly interconnected digital landscapes that support learning management platforms, student information systems, institutional repositories, and online assessment environments. As these systems increasingly operate across cloud infrastructures and mobile devices, ensuring the confidentiality, integrity, and availability (CIA Triad) [...] Read more.
Educational information systems have evolved into highly interconnected digital landscapes that support learning management platforms, student information systems, institutional repositories, and online assessment environments. As these systems increasingly operate across cloud infrastructures and mobile devices, ensuring the confidentiality, integrity, and availability (CIA Triad) of educational data is critical for safeguarding institutional operations and maintaining trust in digital education services. This paper investigates how next-generation security protocols, such as adaptive multi-factor authentication and advanced access control and data protection mechanisms, can reinforce ISO/IEC 27001:2022 requirements within contemporary educational information systems. The analysis maps emerging protocol capabilities to relevant new ISO/IEC 27001:2022 control domains, illustrating how they mitigate threats associated with unauthorized access, data manipulation, and service disruption. The proposed framework is further supported by an implementation-oriented mapping and an illustrative operational architecture that demonstrates the feasibility of translating prioritized security determinants into practical mechanisms. The FAHP analysis identifies access control mechanisms, backup and recovery, and data validation as the three highest-weighted determinants, with aggregate weights of 0.061, 0.059, and 0.057, respectively. These determinants are translated into a determinant-driven Security Operationalization Matrix that connects ISO/IEC 27001:2022 control domains, CIA dimensions, and technology recommendations, and is complemented by implementation feasibility considerations tailored to the budgetary, infrastructural, and resource constraints characteristic of educational institutions. Based on the prioritization results and conceptual operationalization, the proposed integrative approach provides a structured and progressively adoptable foundation for CIA-oriented security governance in digital educational environments. Full article
(This article belongs to the Section Applied Industrial Technologies)
Show Figures

Graphical abstract

19 pages, 2931 KB  
Article
Enhancing the Adoption of Zero Trust in Organizations Using Machine Learning
by Aeshah Mohammed Alshehri, Samer H. Atawneh, Hussein Al Bazar and Roxane Elias Mallouhy
Future Internet 2026, 18(6), 278; https://doi.org/10.3390/fi18060278 - 24 May 2026
Viewed by 1131
Abstract
Cybersecurity has become a critical concern for individuals, organizations, and governments, especially with the rise of sophisticated cyberattacks and remote work environments. Traditional security approaches are no longer sufficient, leading to the adoption of advanced frameworks such as the zero-trust model, which operates [...] Read more.
Cybersecurity has become a critical concern for individuals, organizations, and governments, especially with the rise of sophisticated cyberattacks and remote work environments. Traditional security approaches are no longer sufficient, leading to the adoption of advanced frameworks such as the zero-trust model, which operates on the principle “never trust, always verify.” This model enforces strict access controls and continuous monitoring across all network activities. Designing an intelligent zero-trust system is challenging due to the complexity of network environments and the evolving nature of malicious threats. This project proposes an advanced zero-trust architecture that integrates machine learning and multi-factor authentication (MFA) to strengthen security. Specifically, it employs Multilayer Perceptron models and k-Nearest Neighbors algorithms to analyze system logs and user behavior, enabling real-time anomaly detection and adaptive authentication mechanisms. The proposed framework is experimentally evaluated using the H-MOG behavioral–contextual authentication dataset, which captures multimodal user interaction patterns and supports continuous authentication analysis within Zero Trust environments. The integration of machine learning enhances the system’s ability to identify suspicious activities quickly and accurately, while MFA provides an additional layer of protection against unauthorized access. Moreover, the proposed framework emphasizes usability, ensuring that enhanced security does not impose excessive burden on users or IT teams. This allows the framework to respond more effectively to potential threats while maintaining usability. Overall, the proposed approach offers a practical and scalable solution that improves detection performance and strengthens continuous authentication and adaptive access control within Zero Trust environments. Full article
Show Figures

Graphical abstract

25 pages, 943 KB  
Article
A Hybrid Multi-Model Framework for Personalized User-Level Anomaly Detection with Data-Driven Threshold Optimization
by Amit Kumar, Wakar Ahmad, Om Pal and Sunil
Computation 2026, 14(5), 102; https://doi.org/10.3390/computation14050102 - 30 Apr 2026
Viewed by 970
Abstract
Modern user authentication systems increasingly need user and device-behavior-aware adaptive mechanisms to detect evolving threats beyond the traditional authentication framework of static credential verification. This paper proposes a hybrid multi-model framework for personalized user-level anomaly detection using a data-driven Hybrid Anomaly Score (HAS). [...] Read more.
Modern user authentication systems increasingly need user and device-behavior-aware adaptive mechanisms to detect evolving threats beyond the traditional authentication framework of static credential verification. This paper proposes a hybrid multi-model framework for personalized user-level anomaly detection using a data-driven Hybrid Anomaly Score (HAS). The primary contribution lies in deriving the HAS using the joint integration of three adaptive attributes: dynamically computed per-user deviation thresholds conditioned on individual behavioral history, profile-age-aware baseline weights reflecting user cohort maturity, and criticality-scaled aggregation with the security impact of each detection methodology. The framework is evaluated on a large-scale real-world dataset and demonstrates strong detection performance, while achieving low inference latency suitable for real-time enterprise deployment. The ablation analysis of the framework confirms that dynamic weighting and personalized threshold substantially improve detection stability and convergence with an effective and deployable solution for large-scale authentication environments. Full article
(This article belongs to the Section Computational Engineering)
Show Figures

Figure 1

20 pages, 2376 KB  
Article
ESP32-Based Hardware Key for Software Application Protection
by Alexandru-Ion Popovici and Florin-Daniel Anton
Appl. Sci. 2026, 16(9), 4251; https://doi.org/10.3390/app16094251 - 27 Apr 2026
Viewed by 1360
Abstract
In the current context, classic software licensing and protection mechanisms based exclusively on host application checks can be circumvented by patching, emulation and replay attacks in user-controlled environments. This paper presents an adaptive hardware key implemented on the ESP32-S3 platform, which externalizes sensitive [...] Read more.
In the current context, classic software licensing and protection mechanisms based exclusively on host application checks can be circumvented by patching, emulation and replay attacks in user-controlled environments. This paper presents an adaptive hardware key implemented on the ESP32-S3 platform, which externalizes sensitive decisions and cryptographic operations from the host application to a dedicated device. The solution combines a device-anchored root of trust (secure boot and flash memory encryption), a PKI-verifiable identity (Public Key Infrastructure X.509 certificate and digital signatures as proof of ownership), hierarchical key derivation to avoid static secrets and the establishment of an authenticated encrypted session for all essential data exchanges. User access is conditioned by three-factor authentication (PIN—Personal Identification Number, TOTP—Time based One Time Password and USB physical presence) and a “code-in-dongle” mechanism, in which the important logic runs on the device and the application receives tokens with limited duration. Experimental validation demonstrates correct provisioning, secure session establishment, negative brute-force testing, as well as lifecycle support via signed OTA (Over-The-Air) with anti-rollback and encrypted backup/recovery. Build reports indicate a balanced flash distribution and available DIRAM (Data/Instruction RAM) margin, while IRAM (Instruction RAM) saturation (99.99%) reflects a normal architectural behavior of the ESP32-S3 unified memory model rather than a capacity constraint. Full article
(This article belongs to the Topic Addressing Security Issues Related to Modern Software)
Show Figures

Figure 1

24 pages, 1564 KB  
Article
Sequential Multimodal Biometric Authentication Fusion System
by Swati Rastogi, Sanoj Kumar, Musrrat Ali and Abdul Rahaman Wahab Sait
Mathematics 2026, 14(7), 1178; https://doi.org/10.3390/math14071178 - 1 Apr 2026
Cited by 1 | Viewed by 1184 | Correction
Abstract
The current study proposes an improved DenseNet-based Sequential Multimodal Biometric Authentication System, involving face and ear modality for better human identification. The architecture is composed of three convolutional layers and two dense layers, which are optimized for obtaining the discriminative spatial representations in [...] Read more.
The current study proposes an improved DenseNet-based Sequential Multimodal Biometric Authentication System, involving face and ear modality for better human identification. The architecture is composed of three convolutional layers and two dense layers, which are optimized for obtaining the discriminative spatial representations in 200 × 200 pixel facial and ear images. Evaluation is performed based on strict 5-fold subject disjoint cross-validation data to ensure the unbiased assessment. The model proposed attained a steady classification accuracy of 97.1 ± 0.79%, and balanced values for Precision, Recall and F1-score under controlled validation conditions, while the Performance analysis including False Acceptance (FAR), False Rejection (FRR) and Equal Error Rate (EER) showed that the EER found is around 1.05% at the optimum operating value. Comparative experiments between parallel feature concatenation and sequential verification techniques show that the sequential framework yields decreased FAR, when compared to the parallel framework, without having a detrimental effect on overall accuracy, while the Statistical validation by analysis of variance shows that the incremental architectural improvements have a significant impact on performance improvements. Findings of this analysis show a “score distribution” that both “single-trait and traditional multifactor systems” exceed the presentation of a novel method for Nex-G authentication solutions. This study advances biometric security by demonstrating how multimodal fusion may address the increasing global demand for robust and privacy-aware authentication methods, thereby setting a standard for intelligent multimodal recognition systems. Full article
Show Figures

Figure 1

26 pages, 791 KB  
Article
A Kyber-Based Lightweight Cloud-Assisted Authentication Scheme for Medical IoT
by He Yan, Zhenyu Wang, Liuming Lin, Jing Sun and Shuanggen Liu
Sensors 2026, 26(7), 2021; https://doi.org/10.3390/s26072021 - 24 Mar 2026
Cited by 1 | Viewed by 944
Abstract
The Medical Internet of Things (MIoT) has promoted smart healthcare through the deep integration of wearable devices, wireless communication, and cloud services. However, this framework faces security risks, as attackers may exploit public channels to impersonate legitimate devices or services and steal sensitive [...] Read more.
The Medical Internet of Things (MIoT) has promoted smart healthcare through the deep integration of wearable devices, wireless communication, and cloud services. However, this framework faces security risks, as attackers may exploit public channels to impersonate legitimate devices or services and steal sensitive data. Therefore, establishing authentication between wearable devices and servers prior to data transmission is crucial. Existing schemes suffer from two critical drawbacks: vulnerability to quantum attacks and excessively high communication overhead, highlighting the need for improved solutions. The authors of this paper present a multi-factor identity authentication protocol to achieve post-quantum security and privacy protection. The scheme integrates lattice-based Kyber key encapsulation and a fuzzy commitment mechanism to secure biological templates and enable post-quantum key agreement. Additionally, hash functions and lightweight error correction codes are employed to reduce terminal communication overhead. The security of the scheme is rigorously proved in the Real-or-Random model, and the analysis confirms that the scheme satisfies common security requirements for wireless networks. The proposed scheme is also compared with existing schemes, and the results demonstrate that it achieves a balance between security and overhead. Full article
(This article belongs to the Special Issue Cyber Security and Privacy in Internet of Things (IoT))
Show Figures

Figure 1

34 pages, 2659 KB  
Article
LightGuardAgents: Secure and Robust Embedded Agents for Internet of Things Devices
by José Caicedo-Ortiz, Juan A. Holgado-Terriza, Pablo Pico-Valencia and Deiber Olivares-Olivares
Information 2026, 17(2), 213; https://doi.org/10.3390/info17020213 - 19 Feb 2026
Viewed by 620
Abstract
This paper presents a novel architecture for creating light agents embedded on Internet of Things (IoT) devices, specifically addressing challenges such as security, scalability, and adaptability. Despite the increasing adoption of agent-based approaches in IoT systems, security and robustness mechanisms are often treated [...] Read more.
This paper presents a novel architecture for creating light agents embedded on Internet of Things (IoT) devices, specifically addressing challenges such as security, scalability, and adaptability. Despite the increasing adoption of agent-based approaches in IoT systems, security and robustness mechanisms are often treated as external or ad hoc components in many existing solutions. This limits their effectiveness in dynamic environments that transmit sensitive and personal data and are, by nature, potentially untrusted. The proposed architecture applies Pyro4 for efficient communication among agents and implements a multi-level security scheme that combines symmetric, asymmetric, and hybrid encryption with Time-Based One-Time Passwords (TOTP)-based authentication. This ensures the data confidentiality and integrity within dynamic IoT environments. A case study validates the “agent of things” concept by confirming key security mechanisms such as agent authentication, multi-factor access control, secure communication, and fault resilience. Qualitative testing proved the architecture effective in mitigating common vulnerabilities in distributed agent environments, achieving high reliability scores in terms of security and performance. Experimental results show that over 75% of agent operations were completed in under 2 milliseconds, with a success rate above 99%, confirming the architecture’s lightweight execution and real-time readiness of the architecture for IoT environments. Therefore, the proposed architecture is particularly useful for researchers and practitioners working on secure IoT systems, embedded multi-agent architectures, and intelligent edge computing environments. Full article
Show Figures

Figure 1

43 pages, 2712 KB  
Review
A Comprehensive Survey of Cybersecurity Threats and Data Privacy Issues in Healthcare Systems
by Ramsha Qureshi and Insoo Koo
Appl. Sci. 2026, 16(3), 1511; https://doi.org/10.3390/app16031511 - 2 Feb 2026
Cited by 15 | Viewed by 11180
Abstract
The rapid digital transformation of healthcare has improved clinical efficiency, patient engagement, and data accessibility, but it has also introduced significant cyber security and data privacy challenges. Healthcare IT systems increasingly rely on interconnected networks, electronic health records (EHRs), tele-medicine platforms, cloud infrastructures, [...] Read more.
The rapid digital transformation of healthcare has improved clinical efficiency, patient engagement, and data accessibility, but it has also introduced significant cyber security and data privacy challenges. Healthcare IT systems increasingly rely on interconnected networks, electronic health records (EHRs), tele-medicine platforms, cloud infrastructures, and Internet of Medical Things (IoMT) devices, which collectively expand the attack surface for cyber threats. This scoping review maps and synthesizes recent evidence on cyber security risks in healthcare, including ransomware, data breaches, insider threats, and vulnerabilities in legacy systems, and examines key data privacy concerns related to patient confidentiality, regulatory compliance, and secure data governance. We also review contemporary security strategies, including encryption, multi-factor authentication, zero-trust architecture, blockchain-based approaches, AI-enabled threat detection, and compliance frameworks such as HIPAA and GDPR. Persistent challenges include integrating robust security with clinical usability, protecting resource-limited hospital environments, and managing human factors such as staff awareness and policy adherence. Overall, the findings suggest that effective healthcare cyber security requires a multi-layered defense combining technical controls, continuous monitoring, governance and regulatory alignment, and sustained organizational commitment to security culture. Future research should prioritize adaptive security models, improved standardization, and privacy-preserving analytics to protect patient data in increasingly complex healthcare ecosystems. Full article
Show Figures

Figure 1

22 pages, 1552 KB  
Article
A Novel Two-Factor Authentication Scheme Based on QR Code Prompt
by Maisam Abbas and Ran-Zan Wang
Symmetry 2026, 18(1), 69; https://doi.org/10.3390/sym18010069 - 31 Dec 2025
Viewed by 2072
Abstract
Ensuring online safety and security is critical as personal data grow increasingly valuable, necessitating robust authentication to protect users from potential threats. The use of current authentication mechanisms often fails to balance user convenience, cost effectiveness, and robustness. This paper addresses these challenges [...] Read more.
Ensuring online safety and security is critical as personal data grow increasingly valuable, necessitating robust authentication to protect users from potential threats. The use of current authentication mechanisms often fails to balance user convenience, cost effectiveness, and robustness. This paper addresses these challenges with a two-factor authentication scheme that leverages QR codes embedded with an encoded prompt in the form of a question-and-answer pair. The primary objective is to enhance security by verifying human presence through user interaction with geometrical patterns displayed on the QR code. Upon scanning the QR code, the user accesses a question and references the geometrical patterns shown on the QR code to answer, verifying human presence and mitigating risks of unauthorized access. The shape patterns on QR codes are tested for user perceptions regarding shape clarity, visual esthetics, and QR code scannability. Experiments demonstrate that shape width, size, and position outlines are interrelated with QR code versions or module sizes. For small versions (v1–5) achieved 92% user satisfaction and 89% scan success with centrally placed shapes and 3–5 px outlines, while larger versions (v10–15) attained 94% visual clarity and 96% scan success using randomly distributed shapes with 1–2 px outlines, resulting in a 40% reduction in authentication time compared to SMS-based OTP. This authentication QR code design is competitive in terms of construction cost and efficiency compared with other multi-factor authentication mechanisms for user verification. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

79 pages, 837 KB  
Article
Critique of Networked Election Systems: A Comprehensive Analysis of Vulnerabilities and Security Measures
by Jason M. Green, Abdolhossein Sarrafzadeh and Mohd Anwar
Information 2026, 17(1), 10; https://doi.org/10.3390/info17010010 - 22 Dec 2025
Cited by 1 | Viewed by 5850
Abstract
The security and integrity of election systems represent fundamental pillars of democratic governance in the 21st century. As electoral processes increasingly rely on networked technologies and digital infrastructures, the vulnerability of these systems to cyber threats has become a paramount concern for election [...] Read more.
The security and integrity of election systems represent fundamental pillars of democratic governance in the 21st century. As electoral processes increasingly rely on networked technologies and digital infrastructures, the vulnerability of these systems to cyber threats has become a paramount concern for election officials, cybersecurity experts, and policymakers worldwide. This paper presents the first comprehensive synthesis and systematic analysis of vulnerabilities across major U.S. election systems, integrating findings from government assessments, security research, and documented incidents into a unified analytical framework. We compile and categorize previously fragmented vulnerability data from multiple vendors, federal advisories (CISA, EAC), and security assessments to construct a holistic view of the election security landscape. Our novel contribution includes (1) the first cross-vendor vulnerability taxonomy for election systems, (2) a quantitative risk assessment framework specifically designed for election infrastructure, (3) systematic mapping of threat actor capabilities against election system components, and (4) the first proposal for honeynet deployment in election security contexts. Through analysis of over 200 authoritative sources, we identify critical security gaps in federal guidelines, quantify risks in networked election components, and reveal systemic vulnerabilities that only emerge through comprehensive cross-system analysis. Our findings demonstrate that interconnected vulnerabilities create risk-amplification factors of 2-5x compared to isolated component analysis, highlighting the urgent need for comprehensive federal cybersecurity standards, improved network segmentation, and enhanced monitoring capabilities to protect democratic processes. Full article
Show Figures

Figure 1

24 pages, 606 KB  
Article
A Secure Blockchain-Based MFA Dynamic Mechanism
by Vassilis Papaspirou, Ioanna Kantzavelou, Yagmur Yigit, Leandros Maglaras and Sokratis Katsikas
Computers 2025, 14(12), 550; https://doi.org/10.3390/computers14120550 - 12 Dec 2025
Cited by 2 | Viewed by 2012
Abstract
Authentication mechanisms attract considerable research interest due to the protective role they offer, and when they fail, the system becomes vulnerable and immediately exposed to attacks. Blockchain technology was recently incorporated to enhance authentication mechanisms through its inherited specifications that cover higher security [...] Read more.
Authentication mechanisms attract considerable research interest due to the protective role they offer, and when they fail, the system becomes vulnerable and immediately exposed to attacks. Blockchain technology was recently incorporated to enhance authentication mechanisms through its inherited specifications that cover higher security requirements. This article proposes a dynamic multi-factor authentication (MFA) mechanism based on blockchain technology. The approach combines a honeytoken authentication method implemented with smart contracts and deploys the dynamic change of honeytokens for enhanced security. Two additional random numbers are inserted into the honeytoken within the smart contract for protection from potential attackers, forming a triad of values. The produced set is then imported into a dynamic hash algorithm that changes daily, introducing an additional layer of complexity and unpredictability. The honeytokens are securely transferred to the user through a dedicated and safe communication channel, ensuring the integrity and confidentiality of this critical authentication factor. Extensive evaluation and threat analysis of the proposed blockchain-based MFA dynamic mechanism (BMFA) demonstrate that it meets high-security standards and possesses essential properties that give prospects for future use in many domains. Full article
(This article belongs to the Special Issue Using New Technologies in Cyber Security Solutions (3rd Edition))
Show Figures

Figure 1

37 pages, 2891 KB  
Systematic Review
Cybersecurity Threats and Defensive Strategies for Small and Medium Firms: A Systematic Mapping Study
by Mujtaba Awan and Abu Alam
Adm. Sci. 2025, 15(12), 481; https://doi.org/10.3390/admsci15120481 - 10 Dec 2025
Cited by 4 | Viewed by 8982
Abstract
Small- and Medium-sized Enterprises (SMEs) play a crucial role in the global economy, accounting for approximately two-thirds of global employment and contributing significantly to the GDP of developed countries. Despite the availability of various cybersecurity standards and frameworks, SMEs remain highly vulnerable to [...] Read more.
Small- and Medium-sized Enterprises (SMEs) play a crucial role in the global economy, accounting for approximately two-thirds of global employment and contributing significantly to the GDP of developed countries. Despite the availability of various cybersecurity standards and frameworks, SMEs remain highly vulnerable to cyber threats. Limited resources and a lack of expertise in cybersecurity make them frequent targets for cyberattacks. It is essential to identify the challenges faced by SMEs and explore effective defensive strategies to enhance the implementation of cybersecurity measures. The study aims to bridge the gap and help these organizations in implementing cost-effective and practical cybersecurity approaches through a systematic mapping study (SMS) conducted, where 73 articles were thoroughly reviewed. This research will shed light on the current cybersecurity approaches (practices) posture for different SMEs, along with the threats they are facing, which have stopped them from deciding, planning, and implementing cybersecurity measures. The study identified a wide range of cybersecurity threats, including phishing, social engineering, insider threats, ransomware, malware, denial of services attacks, and weak password practices, which are the most prevalent for SMEs. This study identified defensive practices, such as cybersecurity awareness and training, endpoint protection tools, incident response planning, network segmentation, access control, multi-factor authentication (MFA), access controls, privilege management, email authentication and encryption, enforcing strong password policies, cloud security, secure backup solutions, supply chain visibility, and automated patch management tools, as key measures. The study provides valuable insights into the specific gaps and challenges faced by SMEs, as well as their preferred methods of seeking and consuming cybersecurity assistance. The findings can guide the development of targeted defensive practices and policies to enhance the cybersecurity posture of SMEs for successful software development. This SMS will also provide a foundation for future research and practical guidelines for SMEs to improve the process of secure software development. Full article
Show Figures

Figure 1

28 pages, 3005 KB  
Article
A Secure and Sustainable Transition from Legacy Smart Cards to Mobile Credentials in University Access Control Systems
by Rashid Mustafa, Toseef Ahmed Khan and Nurul I. Sarkar
Information 2025, 16(12), 1073; https://doi.org/10.3390/info16121073 - 4 Dec 2025
Cited by 2 | Viewed by 1985
Abstract
A secure and sustainable building access control system plays a vital role in protecting organisational assets worldwide. Physical access management at Auckland University of Technology (AUT) is still primarily done through traditional card-based authentication. The system is susceptible to replay and cloning attacks [...] Read more.
A secure and sustainable building access control system plays a vital role in protecting organisational assets worldwide. Physical access management at Auckland University of Technology (AUT) is still primarily done through traditional card-based authentication. The system is susceptible to replay and cloning attacks because the conventional Mifare Classic credentials employ outdated Crypto1 encryption. Such weaknesses provide significant threats in laboratories, engineering testing facilities, and research and technological areas that require strict security procedures. To overcome the above issues, we propose a secure and sustainable university building access control system using mobile app credentials. This research grounded a thorough risk analysis of the university’s current infrastructure, mapping potential operational continuity threats. We analyse card issuance records by identifying high-risk areas such as restricted laboratories and evaluating the resilience of the current Gallagher–Salto system against cloning and replay attacks. We quantify the distribution and usage of cards that are vulnerable. To evaluate the risks to operational continuity, the system architecture is examined. Additionally, a trial implementation of the Gallagher Mobile Connect platform was conducted, utilising cloud registration, multi-factor authentication (PIN or biometrics), and books. Pilot implementation shows that mobile-based credentials improve user experience, align with AUT’s environmental sustainability roadmap, and increase resilience against known attacks. Results have shown that our proposed mobile credentials can improve the system performance up to 80%. Full article
Show Figures

Figure 1

Back to TopTop