{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T15:54:27Z","timestamp":1781020467351,"version":"3.54.1"},"reference-count":41,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T00:00:00Z","timestamp":1765497600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>Authentication mechanisms attract considerable research interest due to the protective role they offer, and when they fail, the system becomes vulnerable and immediately exposed to attacks. Blockchain technology was recently incorporated to enhance authentication mechanisms through its inherited specifications that cover higher security requirements. This article proposes a dynamic multi-factor authentication (MFA) mechanism based on blockchain technology. The approach combines a honeytoken authentication method implemented with smart contracts and deploys the dynamic change of honeytokens for enhanced security. Two additional random numbers are inserted into the honeytoken within the smart contract for protection from potential attackers, forming a triad of values. The produced set is then imported into a dynamic hash algorithm that changes daily, introducing an additional layer of complexity and unpredictability. The honeytokens are securely transferred to the user through a dedicated and safe communication channel, ensuring the integrity and confidentiality of this critical authentication factor. Extensive evaluation and threat analysis of the proposed blockchain-based MFA dynamic mechanism (BMFA) demonstrate that it meets high-security standards and possesses essential properties that give prospects for future use in many domains.<\/jats:p>","DOI":"10.3390\/computers14120550","type":"journal-article","created":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T11:13:33Z","timestamp":1765538013000},"page":"550","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Secure Blockchain-Based MFA Dynamic Mechanism"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-6361-2797","authenticated-orcid":false,"given":"Vassilis","family":"Papaspirou","sequence":"first","affiliation":[{"name":"Department of Informatics and Computer Engineering, Faculty of Engineering, University of West Attica, Egaleo Park Campus, 12243 Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5976-7837","authenticated-orcid":false,"given":"Ioanna","family":"Kantzavelou","sequence":"additional","affiliation":[{"name":"Department of Informatics and Computer Engineering, Faculty of Engineering, University of West Attica, Egaleo Park Campus, 12243 Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4311-393X","authenticated-orcid":false,"given":"Yagmur","family":"Yigit","sequence":"additional","affiliation":[{"name":"School of Computing, Engineering and the Built Environment, Edinburgh Napier University, 10 Colinton Road, Edinburgh EH10 5DT, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5360-9782","authenticated-orcid":false,"given":"Leandros","family":"Maglaras","sequence":"additional","affiliation":[{"name":"School of Computing, Engineering and the Built Environment, Edinburgh Napier University, 10 Colinton Road, Edinburgh EH10 5DT, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2966-9683","authenticated-orcid":false,"given":"Sokratis","family":"Katsikas","sequence":"additional","affiliation":[{"name":"Norwegian Centre for Cybersecurity in Critical Sectors (NORCICS), 7491 Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,12]]},"reference":[{"key":"ref_1","first-page":"708","article-title":"Two birds with one stone: Two-factor authentication with security beyond conventional bound","volume":"15","author":"Wang","year":"2016","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Petruni\u0107, A.R. (2015, January 25\u201329). Honeytokens as active defense. Proceedings of the 2015 38th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO), Opatija, Croatia.","DOI":"10.1109\/MIPRO.2015.7160478"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Papaspirou, V., Maglaras, L., Ferrag, M.A., Kantzavelou, I., Janicke, H., and Douligeris, C. (2021). A novel two-factor honeytoken authentication mechanism. Proceedings of the 2021 International Conference on Computer Communications and Networks (ICCCN), IEEE.","DOI":"10.1109\/ICCCN52240.2021.9522319"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"16917","DOI":"10.1109\/JIOT.2022.3146197","article-title":"Secure, efficient, and weighted access control for cloud-assisted industrial IoT","volume":"9","author":"Li","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_5","unstructured":"Papaspirou, V., Kantzavelou, I., Yigit, Y., Maglaras, L., and Katsikas, S. (August, January 30). A Blockchain-based Multi-Factor Honeytoken Dynamic Authentication Mechanism. Proceedings of the 19th International Conference on Availability, Reliability and Security, Vienna, Austria."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"50759","DOI":"10.1109\/ACCESS.2019.2911031","article-title":"Security, performance, and applications of smart contracts: A systematic survey","volume":"7","author":"Rouhani","year":"2019","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"61048","DOI":"10.1109\/ACCESS.2021.3072849","article-title":"A survey on blockchain technology: Evolution, architecture and security","volume":"9","author":"Bhutta","year":"2021","journal-title":"IEEE Access"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Amrutiya, V., Jhamb, S., Priyadarshi, P., and Bhatia, A. (2019, January 9\u201311). Trustless two-factor authentication using smart contracts in blockchains. Proceedings of the 2019 International Conference on Information Networking (ICOIN), Kuala Lumpur, Malaysia.","DOI":"10.1109\/ICOIN.2019.8718198"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1016\/j.ijmedinf.2019.04.019","article-title":"Evaluating information security core human error causes (IS-CHEC) technique in public sector and comparison with the private sector","volume":"127","author":"Evans","year":"2019","journal-title":"Int. J. Med. Inform."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Sun, H., Sun, K., Wang, Y., and Jing, J. (2015, January 12\u201316). TrustOTP: Transforming smartphones into secure one-time password tokens. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA.","DOI":"10.1145\/2810103.2813692"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"ALSaleem, B.O., and Alshoshan, A.I. (2021, January 27\u201328). Multi-factor authentication to systems login. Proceedings of the 2021 National Computing Colleges Conference (NCCC), Taif, Saudi Arabia.","DOI":"10.1109\/NCCC49330.2021.9428806"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Thompson, A., Abayomi, A., and Gabriel, A.J. (2022). Multifactor IoT Authentication System for Smart Homes Using Visual Cryptography, Digital Memory, and Blockchain Technologies. Blockchain Applications in the Smart Era, Springer.","DOI":"10.1007\/978-3-030-89546-4_14"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Kebande, V.R., Awaysheh, F.M., Ikuesan, R.A., Alawadi, S.A., and Alshehri, M.D. (2021). A blockchain-based multi-factor authentication model for a cloud-enabled internet of vehicles. Sensors, 21.","DOI":"10.20944\/preprints202107.0429.v1"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Buccafurri, F., De Angelis, V., and Nardone, R. (2020). Securing mqtt by blockchain-based otp authentication. Sensors, 20.","DOI":"10.3390\/s20072002"},{"key":"ref_15","unstructured":"(2025, December 07). Multi-Factor Authentication Number Matching. Available online: https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/how-to-mfa-number-match?tabs=iOS."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"74","DOI":"10.26594\/register.v6i2.1932","article-title":"Two factor authentication framework based on ethereum blockchain with dApp as token generation system instead of third-party on web application","volume":"6","author":"Putri","year":"2020","journal-title":"Register"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Mercan, S., Cebe, M., Akkaya, K., and Zuluaga, J. (2021). Blockchain-Based Two-Factor Authentication for Credit Card Validation. Proceedings of the International Workshop on Data Privacy Management, Springer.","DOI":"10.1007\/978-3-030-93944-1_22"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Chen, W., Zheng, Z., Cui, J., Ngai, E., Zheng, P., and Zhou, Y. (2018, January 23\u201327). Detecting ponzi schemes on ethereum: Towards healthier blockchain technology. Proceedings of the 2018 World Wide Web Conference, Lyon, France.","DOI":"10.1145\/3178876.3186046"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1928","DOI":"10.1109\/TMC.2024.3488746","article-title":"LiteChain: A lightweight blockchain for verifiable and scalable federated learning in massive edge networks","volume":"24","author":"Chen","year":"2024","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_20","unstructured":"Akanda, M.M.R.R., Lacy, A., and Saxena, N. (2025, January 13\u201315). {SoK}: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in {State-of-the-Art} Academic Proposals. Proceedings of the 34th USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Papaspirou, V., Papathanasaki, M., Maglaras, L., Kantzavelou, I., Douligeris, C., Ferrag, M.A., and Janicke, H. (2022, January 23\u201325). Security Revisited: Honeytokens meet Google Authenticator. Proceedings of the 2022 7th South-East Europe Design Automation, Computer Engineering, Computer Networks and Social Media Conference (SEEDA-CECNSM), Ioannina, Greece.","DOI":"10.1109\/SEEDA-CECNSM57760.2022.9932907"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Otta, S.P., Panda, S., Gupta, M., and Hota, C. (2023). A systematic survey of multi-factor authentication for cloud infrastructure. Future Internet, 15.","DOI":"10.3390\/fi15040146"},{"key":"ref_23","unstructured":"Ross, R.S. (2025, December 07). Guide for Conducting Risk Assessments, Available online: https:\/\/nvlpubs.nist.gov\/nistpubs\/legacy\/sp\/nistspecialpublication800-30r1.pdf."},{"key":"ref_24","unstructured":"(2011). Managing Information Security Risk: Organization, Mission, and Information System View (Standard No. SP 800-39)."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"140549","DOI":"10.1109\/ACCESS.2021.3119291","article-title":"The 51% attack on blockchains: A mining behavior study","volume":"9","author":"Orozco","year":"2021","journal-title":"IEEE Access"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Platt, M., and McBurney, P. (2023). Sybil in the haystack: A comprehensive review of blockchain consensus mechanisms in search of strong Sybil attack resistance. Algorithms, 16.","DOI":"10.3390\/a16010034"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"6605","DOI":"10.1109\/ACCESS.2021.3140091","article-title":"Systematic review of security vulnerabilities in ethereum blockchain smart contract","volume":"10","author":"Kushwaha","year":"2022","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1016\/bs.adcom.2020.08.020","article-title":"Attacks on blockchain","volume":"121","author":"Aggarwal","year":"2021","journal-title":"Advances in Computers"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Joshi, K., Bhatt, C., Shah, K., Parmar, D., Corchado, J.M., Bruno, A., and Mazzeo, P.L. (2023). Machine-learning techniques for predicting phishing attacks in blockchain networks: A comparative study. Algorithms, 16.","DOI":"10.3390\/a16080366"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Alkhalifah, A., Ng, A., Watters, P.A., and Kayes, A. (2021). A mechanism to detect and prevent ethereum blockchain smart contract reentrancy attacks. Front. Comput. Sci., 3.","DOI":"10.3389\/fcomp.2021.598780"},{"key":"ref_31","unstructured":"(2025, December 07). Security Considerations: Reentrancy. Available online: https:\/\/docs.soliditylang.org\/en\/latest\/security-considerations.html."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1659","DOI":"10.1109\/TNSM.2021.3069502","article-title":"Decentralized and lightweight approach to detect eclipse attacks on proof of work blockchains","volume":"18","author":"Alangot","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_33","unstructured":"Dwivedi, K., Agrawal, A., Bhatia, A., and Tiwari, K. (2024). A novel classification of attacks on blockchain layers: Vulnerabilities, attacks, mitigations, and research directions. arXiv."},{"key":"ref_34","first-page":"20","article-title":"Blockchain Threats: A Look into the Most Common Forms of Cryptocurrency Attacks","volume":"6","author":"Zolkipli","year":"2023","journal-title":"Borneo Int. J."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"76153","DOI":"10.1109\/ACCESS.2021.3081998","article-title":"Exploring sybil and double-spending risks in blockchain systems","volume":"9","author":"Iqbal","year":"2021","journal-title":"IEEE Access"},{"key":"ref_36","unstructured":"Zhang, M., Zhang, X., Zhang, Y., and Lin, Z. (October, January 30). Security of cross-chain bridges: Attack surfaces, defenses, and open problems. Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses, Padua, Italy."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Qin, K., Zhou, L., Livshits, B., and Gervais, A. (2021). Attacking the defi ecosystem with flash loans for fun and profit. Proceedings of the International Conference on Financial Cryptography and Data Security, Springer.","DOI":"10.1007\/978-3-662-64322-8_1"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Choi, J., Ahn, B., Bere, G., Ahmad, S., Mantooth, H.A., and Kim, T. (2021, January 14\u201315). Blockchain-based man-in-the-middle (MITM) attack detection for photovoltaic systems. Proceedings of the 2021 IEEE Design Methodologies Conference (DMC), Virtually.","DOI":"10.1109\/DMC51747.2021.9529949"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Byun, H., Kim, J., Jeong, Y., Seok, B., Gong, S., and Lee, C. (2024). A Security Analysis of Cryptocurrency Wallets against Password Brute-Force Attacks. Electronics, 13.","DOI":"10.3390\/electronics13132433"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"383","DOI":"10.1016\/j.eij.2022.03.001","article-title":"Cybersecurity decision support model to designing information technology security system based on risk analysis and cybersecurity framework","volume":"23","author":"Razikin","year":"2022","journal-title":"Egypt. Inform. J."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1279","DOI":"10.1007\/s11276-024-03818-x","article-title":"EtherVote: A Secure Smart Contract-based E-Voting System","volume":"31","author":"Spanos","year":"2025","journal-title":"Wirel. Netw"}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/14\/12\/550\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T11:21:42Z","timestamp":1765538502000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/14\/12\/550"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,12]]},"references-count":41,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["computers14120550"],"URL":"https:\/\/doi.org\/10.3390\/computers14120550","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,12]]}}}