Transition to Password-Free and Phishing-Resistant Authentication in Enterprise Information Systems: A FIDO2/Passkey-Based Standards-Based Qualitative Assessment and Phased Implementation Framework
Jul 2026· International Journal For Multidisciplinary Research· Vol 8· 0 citations· 12 references
TL;DR
This passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain and proposes Enterprises five-phase migration.
Abstract
Password-based authentication is one of the most fundamental vulnerabilities of enterprise information systems. This vulnerability is exploited through phishing, credential stuffing, password reuse and real-time transmission attacks where an attacker intercepts data. With strong multi-factor authentication, the risk is minimized but human-mediated factors like SMS, time-based OTP, confirmation notifications may get affected through fake login pages and reverse proxy. In general, the paper presents an evaluation of the security, usability, recovery, governance and interoperability aspects of FIDO2/WebAuthn and passkey which to be used for enterprise authentication. As per standards and current research, the study is qualitative risk comparison of password, password+OTP, push MFA, device-bound passkey and synchronized passkey approach; it establishes threat-control mapping; and proposes Enterprises five-phase migration. Consequently, as the proof demonstrates, this passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain. Nonetheless, reliance on synchronization provider, account recovery processes, legacy applications, multi-user-device usage, loss of devices, and enterprise attestation requirements generate new clusters of risks. The framework will consist of the following phases: inventory and user segmentation; pilot implementation for high-risk accounts; rollout to the managed workforce; and recovery and telemetry optimisation towards a managed de-risking against passwords. According to the research, the deployment of passkeys should not merely be regarded as a new technology for logging in. When used, a passkey can be thought of as a comprehensive enterprise security programme that jointly transforms the identity lifecycle, help desk, device management, access policies, and incident response.
Single Sign-On (SSO) is now a common way to log in to cloud platforms, enterprise systems, mobile apps, and shared digital services, but traditional deployments remain vulnerable to credential leakage, phishing, token theft, replay attacks, and identity-provider compromise. Recent research has turned to threshold crypt...
Shashank Angadi· 2026 International Conferenc...· 0 citations
Password authentication remains widely used, but modern phishing campaigns increasingly target the authenticated session rather than the password alone. This study examines the gradual erosion of password-based security through a reproducible secondary-data analysis of phishing websites and network intrusions, while al...
Tommi Michael Pallarco, Bernice Jennifer Bontalilid, Jose Arno Gamboa et al.· International journal of res...· 0 citations
This paper proposes a secure approach to enhance private key synchronization mechanisms in passkeys systems using Elliptic Curve Diffie-Hellman protocol and Zero-Knowledge Proofs in a peer-to-peer environment.
Assane Ilboudo, Didier Bassolé, Désiré Guel· EPJ Web of Conferences· 0 citations
One-Time Passwords (OTPs) have become a common option for multi-factor authentication in several applications. For instance, during website login processes, OTPs are often used in conjunction with traditional text-based usernames and passwords to verify whether the access request originates from a legitimate human user...
The escalation of cyber-attacks has intensified the need for stronger multi-factor authentication (MFA), motivating a shift from traditional knowledge- and possession-based factors, such as SMS one-time passwords (OTP) and time-based one-time passwords (TOTP), toward FIDO2/WebAuthn credentials and passkeys. This study...
F. Folorunsho, Zubair Odeleye· GlobeIS International Journa...· 0 citations
Healthcare mobile applications increasingly expose scheduling, messaging, billing, medication, and clinical-information services through cloud APIs. This creates an identity boundary that must resist credential theft, token interception, session replay, privilege misuse, and fragmented account governance without imposi...
Muhammed Harris Kodavath Saidumuhammed· International Journal of Com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.