• DocumentCode
    185890
  • Title

    A Two-Factor Authentication System with QR Codes for Web and Mobile Applications

  • Author

    Eminagaoglu, Mete ; Cini, Ece ; Sert, Gizem ; Zor, Derya

  • Author_Institution
    Dept. of Software Eng., Yasar Univ., Izmir, Turkey
  • fYear
    2014
  • fDate
    10-12 Sept. 2014
  • Firstpage
    105
  • Lastpage
    112
  • Abstract
    The use of QR code-based technologies and applications has become prevalent in recent years where QR codes are accepted to be a practical and intriguing data representation / processing mechanism amongst worldwide users. The aim of this study is to design and implement an alternative two-factor identity authentication system by using QR codes and to make the relevant mechanism and process that could be more user-friendly and practical than one-time password mechanisms used with similar purposes today. The proposed model in this project has been designed in order to enable the verification and validation steps with several security and networking options during the logon process. The model has been implemented by developing a two-factor identity verification system where the second factor is the user´s smart / mobile phone device and a pseudo-randomly generated alphanumerical QR code which is used as the one-time password token sent to the user via e-mail or MMS. The proposed model has been developed using C#, asp.net and jQuery languages with symmetrical and asymmetrical cryptography standards for database encryption / hashing and network infrastructure and it has been tested as a prototype where promising results are observed regarding the efficiency, speed and security requirements for today´s on-line financial services and similar e-commerce systems.
  • Keywords
    C language; Internet; QR codes; cryptography; electronic commerce; financial data processing; mobile computing; C#; MMS; Web applications; asp.net; cryptography standards; data processing mechanism; data representation mechanism; database encryption; e-commerce systems; e-mail; hashing; jQuery languages; logon process security; mobile applications; mobile phone device; one-time password token; online financial services; pseudorandomly generated alphanumerical QR code; smart phone device; two-factor identity authentication system; two-factor identity verification system; Security; QR codes; cryptography; mobile phone; one-time password; two-factor authentication; web camera;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Security Technologies (EST), 2014 Fifth International Conference on
  • Conference_Location
    Alcala de Henares
  • Type

    conf

  • DOI
    10.1109/EST.2014.19
  • Filename
    6982784