Usability Evaluation of a Push‐Based Passwordless Authentication Model Using Public‐Key Cryptography
Ghulam Mustafa, Shah Zaman Nizamani, Irfana Memon, Asif Ali Wagan, Соломія Федушко, Abdullah Al Hejaili · IET Biometrics · 2026
Despite major advancements in the sphere of the public‐key authentication specifically in the instances of the newly established standards like WebAuthn and the FIDO2, the practical implementation of the passwordless login systems is still hindered by the usability factors, platform‐related requirements, and the very nature of the deployment process is predetermined by its complex character. We formulate in this contribution a practical, push‐based authentication model, which takes active advantage of the utilization of the public‐key cryptography, combined with the traditional set of capabilities in mobile devices, to provide a secure and consumer‐friendly way of logging into a system. The architecture has been implemented using the Laravel web application framework, the Flutter cross‐platform mobile development system, and Firebase Cloud Messaging (FCM), thus enabling authentication using smartphone‐initiated approvals and digital signatures. A within‐subject usability experiment with 160 participants was the measure of effectiveness of the proposed approach. The participants were requested to fulfill the tasks of logins with the postulated push‐based mechanism and an experimental password‐based one. System logs provided objective metrics such as the latency to log in, rate of errors, and the success rate of the first attempt. At the same time, the subjective ratings were gathered through the means of structured questionnaires where the ease of use, speed, security, and preferences were measured. Empirical data revealed that despite the insignificant increase in time of login, the passwordless system reported a significant decrease in error, increase in success rate, and a significant preference among the subjects in all the dimensions of usability that were being tested. Each of the observed differences was statistically significant and with large effect sizes. This research provides a deplorable, platform adaptable authentication paradigm that preempts realistic coping, yet holds core security standards. Emphasizing the need to balance system design with human‐centered assessment the work suggests a possible solution to more complex or more hardware‐resources limited passwordless usage.