Skip to content
Open access

Transition to Password-Free and Phishing-Resistant Authentication in Enterprise Information Systems: A FIDO2/Passkey-Based Standards-Based Qualitative Assessment and Phased Implementation Framework

Jul 2026 · International Journal For Multidisciplinary Research · Vol 8 · 0 citations · 12 references

TL;DR

This passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain and proposes Enterprises five-phase migration.

Abstract

Password-based authentication is one of the most fundamental vulnerabilities of enterprise information systems. This vulnerability is exploited through phishing, credential stuffing, password reuse and real-time transmission attacks where an attacker intercepts data. With strong multi-factor authentication, the risk is minimized but human-mediated factors like SMS, time-based OTP, confirmation notifications may get affected through fake login pages and reverse proxy. In general, the paper presents an evaluation of the security, usability, recovery, governance and interoperability aspects of FIDO2/WebAuthn and passkey which to be used for enterprise authentication. As per standards and current research, the study is qualitative risk comparison of password, password+OTP, push MFA, device-bound passkey and synchronized passkey approach; it establishes threat-control mapping; and proposes Enterprises five-phase migration. Consequently, as the proof demonstrates, this passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain. Nonetheless, reliance on synchronization provider, account recovery processes, legacy applications, multi-user-device usage, loss of devices, and enterprise attestation requirements generate new clusters of risks. The framework will consist of the following phases: inventory and user segmentation; pilot implementation for high-risk accounts; rollout to the managed workforce; and recovery and telemetry optimisation towards a managed de-risking against passwords. According to the research, the deployment of passkeys should not merely be regarded as a new technology for logging in. When used, a passkey can be thought of as a comprehensive enterprise security programme that jointly transforms the identity lifecycle, help desk, device management, access policies, and incident response.

Read PDF

Similar papers

Conference Aug 2026

Threshold Cryptography for Leakage-Resilient Single Sign-On: A Comparative Security Analysis and Architecture Framework

Single Sign-On (SSO) is now a common way to log in to cloud platforms, enterprise systems, mobile apps, and shared digital services, but traditional deployments remain vulnerable to credential leakage, phishing, token theft, replay attacks, and identity-provider compromise. Recent research has turned to threshold crypt...

Shashank Angadi · 0 citations
Open access 2026

The Erosion of Password-Based Authentication Security: A Data-Driven Evaluation of Phishing-Based Session Hijacking and MFA-Bypass Techniques

Password authentication remains widely used, but modern phishing campaigns increasingly target the authenticated session rather than the password alone. This study examines the gradual erosion of password-based security through a reproducible secondary-data analysis of phishing websites and network intrusions, while al...

Tommi Michael Pallarco, Bernice Jennifer Bontalilid, Jose Arno Gamboa et al. · 0 citations
Conference Open access 2026

Enhanced Private key Synchronization Mechanism Security in Passkeys System Based on Elliptic Curve Diffie-Hellman and Zero-Knowledge Proofs

This paper proposes a secure approach to enhance private key synchronization mechanisms in passkeys systems using Elliptic Curve Diffie-Hellman protocol and Zero-Knowledge Proofs in a peer-to-peer environment.

Assane Ilboudo, Didier Bassolé, Désiré Guel · 0 citations
Preprint Aug 2026

Quantum-Safe Web Service Architecture Using Time-Based One-Time Passwords

One-Time Passwords (OTPs) have become a common option for multi-factor authentication in several applications. For instance, during website login processes, OTPs are often used in conjunction with traditional text-based usernames and passwords to verify whether the access request originates from a legitimate human user...

Abel C. H. Chen · 0 citations
Open access Aug 2026

Comparing Multi-Factor Authentication Methods from SMS and TOTP to FIDO2/WebAuthn and Passkeys: A Qualitative Study of Practitioner Perspectives

The escalation of cyber-attacks has intensified the need for stronger multi-factor authentication (MFA), motivating a shift from traditional knowledge- and possession-based factors, such as SMS one-time passwords (OTP) and time-based one-time passwords (TOTP), toward FIDO2/WebAuthn credentials and passkeys. This study...

F. Folorunsho, Zubair Odeleye · 0 citations
Open access Aug 2026

MULTI-FACTOR AUTHENTICATION, SINGLE SIGN-ON, AND IDENTITY MANAGEMENT IN CLOUD-BASED HEALTHCARE MOBILE APPLICATIONS A Reference Architecture and STRIDE Threat-Model Evaluation

Healthcare mobile applications increasingly expose scheduling, messaging, billing, medication, and clinical-information services through cloud APIs. This creates an identity boundary that must resist credential theft, token interception, session replay, privilege misuse, and fragmented account governance without imposi...

Muhammed Harris Kodavath Saidumuhammed · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.