Improving Resource Security by Integrating Authentication and Cryptography
Zina Oudina, Makhlouf Derdour, Mohammed Mounir Bouhamed · 2024
Protecting digital identities becomes critical due to the ever-evolving sophistication of cyber threats. Organizations seek to secure their resources and the secure processing of personal data through proper technical and organizational measures. They also seek to secure personal data and protect against unauthorized or unlawful processing. Organizations can ensure the security of their networks by restricting access to protected resources exclusively to authenticated users or processes. This category encompasses databases, web pages, wireless networks, personal computers, and other network-based programs and services. Authentication plays a pivotal role in this process, as it verifies the identity of a registered user or process before granting access to sensitive resources and systems. Organizations now embrace the idea that access should be challenging for hackers but easy for authorized users. Multi-factor authentication (MFA) is one of the most effective approaches to achieve this. A password is a security measure and one factor that protects against unauthorized users. Passwords alone are acknowledged as one of the most basic targets of hackers. Existing 2FA schemes are vulnerable to numerous security attacks because they only use a Personal Identification Number (PIN) and Subscriber Identity Module (SIM). Since biometrics are considered extremely safe, they are employed in specific organisations. This study proposes secure access to protected resources using multi-factor authentication, combining encrypted passwords, PIN1, PIN2, and fingerprints. A SWOT analysis is performed to assess the proposed approach.