A novel Two-Factor HoneyToken Authentication Mechanism
Vassilis Papaspirou, Leandros Maglaras, Mohamed Amine Ferrag, Ioanna, Kantzavelou, Helge Janicke, Christos Douligeris

TL;DR
This paper introduces a new two-factor authentication system combined with Honeyword principles to improve security against password theft and unauthorized access, using QR codes and mobile phones for easy integration.
Contribution
It presents a novel Two-Factor HoneyToken Authentication Mechanism that enhances security by combining two-factor authentication with honeyword-based detection methods.
Findings
Improves detection of stolen or compromised tokens.
Enhances security against unauthorized system access.
Integrates seamlessly with existing platforms using QR codes.
Abstract
The majority of systems rely on user authentication on passwords, but passwords have so many weaknesses and widespread use that easily raise significant security concerns, regardless of their encrypted form. Users hold the same password for different accounts, administrators never check password files for flaws that might lead to a successful cracking, and the lack of a tight security policy regarding regular password replacement are a few problems that need to be addressed. The proposed research work aims at enhancing this security mechanism, prevent penetrations, password theft, and attempted break-ins towards securing computing systems. The selected solution approach is two-folded; it implements a two-factor authentication scheme to prevent unauthorized access, accompanied by Honeyword principles to detect corrupted or stolen tokens. Both can be integrated into any platform or web…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
