Zero-Trust Multi-Factor Authentication for Secure Digital Payments: Design and Implementation

Carasiola, Farrel Alfared and Putra, Rakhmadi Irfansyah (2026) Zero-Trust Multi-Factor Authentication for Secure Digital Payments: Design and Implementation. Zero Trust Multi-Factor Authentication for Secure Digital Payments: Design and Implementation, 2 (8). pp. 1-14.

[thumbnail of Article_202231003_Farrel Alfared Carasiola.pdf] Text
Article_202231003_Farrel Alfared Carasiola.pdf

Download (721kB)

Abstract

Digital payment security requires robust access protection against unauthorized login attempts, credential misuse, and device-based threats. This study designs and implements a Zero Trust architecture-based Multi-Factor Authentication (MFA) prototype to strengthen access control in digital payment applications. The proposed system integrates password-based authentication, Time-Based One-Time Password (TOTP), device-trust evaluation, adaptive step-up authentication, rate limiting, and audit logging in a single authentication workflow. The novelty lies in integrating Zero Trust principles with MFA and device-based contextual verification, so access decisions consider both user credentials and device trust. The prototype was implemented using a client-server architecture with Flask as the backend and PostgreSQL as the database. Evaluation was conducted using 50 automated test cases across five authentication scenarios: valid registered-device login, invalid password, invalid OTP, new-device login, and expired OTP. The results show that the proposed system achieved 100% detection accuracy, 0% Attack Success Rate (ASR), 0% False Acceptance Rate (FAR), 0% False Rejection Rate (FRR), 100% Authentication Success Rate, and 100% Step-Up Trigger Rate. Performance testing showed an average authentication latency of 197.45 ms with a standard deviation of 5.18 ms, indicating stable and responsive authentication performance. A preliminary usability assessment also indicated that the login, TOTP verification, and step-up authentication workflow remained understandable without unnecessary authentication friction. Overall, the proposed prototype provides a practical baseline for strengthening digital payment access security through Zero Trust-based MFA and context-aware authentication.

Item Type: Article
Uncontrolled Keywords: digital payment security; zero trust architecture; multi-factor authentication (MFA); time-based one-time password (TOTP); step-up authentication.
Subjects: Bidang Keilmuan > Algoritma
Bidang Keilmuan > Blockchain Technology
Bidang Keilmuan > Convolutional System
Bidang Keilmuan > Data Analytics
Bidang Keilmuan > Data Clustering
Bidang Keilmuan > Data Science
Bidang Keilmuan > Database
Bidang Keilmuan > Decision Making
Bidang Keilmuan > Deep learning
Jurnal
Bidang Keilmuan > Machine Learning
Bidang Keilmuan > Smart System
Bidang Keilmuan > Software Development
Bidang Keilmuan > Teknik Informatika
Bidang Keilmuan > Information Technology
Divisions: Fakultas Telematika Energi > S1 Teknik Informatika
Depositing User: FAKULTAS TELEMATIKA ENERGI
Date Deposited: 20 Aug 2026 03:59
Last Modified: 21 Sep 2026 06:47
URI: https://repository.itpln.ac.id/id/eprint/7016

Actions (login required)

View Item
View Item