📖 ABSTRACT/OVERVIEW
Single-factor password authentication on the University of Nigeria, Nsukka student portal leaves user accounts vulnerable to credential theft, brute-force attacks, and phishing, risking unauthorized access to sensitive academic records. This study designs and evaluates a multi-factor authentication (MFA) system for the UNN student information portal, incorporating password authentication, time-based one-time password (TOTP) generation via a mobile authenticator, and an optional biometric fingerprint fallback for campus-based access points. The MFA architecture was integrated as a middleware layer within the existing Laravel-based portal backend. TOTP implementation followed the RFC 6238 standard using the PHP OTPHP library. Fingerprint verification at campus kiosks was managed through a ZFM-60 module linked to the server via a RESTful API. System evaluation involved 150 student volunteers over four weeks, with penetration testing conducted by a supervised security evaluation team. Results indicate that unauthorized access attempts were blocked in 100 percent of simulated credential theft scenarios. Account login time increased by an average of 12 seconds due to the additional authentication step, which 78 percent of participants rated as an acceptable trade-off. TOTP delivery success rate via the authenticator app was 99.1 percent. The study concludes that MFA implementation on UNN's student portal substantially strengthens access security. Recommendations include staff portal extension and phased biometric expansion to all campus access points.
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬