
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
Yash Vinod Tayade1 , Mrs. Neha N. Jamdar2 , Dr. Emmanuel Markappa3
1Dept. of Information Technology, Pune Institute of Computer Technology, Pune, Maharashtra, India
2Professor, Dept. of Information Technology, Pune Institute of Computer Technology, Pune, Maharashtra, India
3Professor, Dept. of Information Technology, Pune Institute of Computer Technology, Pune, Maharashtra, India
Abstract - Authentication is the main gatekeeper in the modern digitalenvironment, preventingaccesstoinformation systemsbyunauthorizedusers. Password-onlyauthentication is susceptible to phishing, brute-force attacks, and credential leaks, which is whytheMulti-FactorAuthentication(MFA)has cometotherescue. MFA makes authenticationmoresecureby using two or more different factors that include knowledge (password), possession (token or mobile device), and inherence (biometrics). Still, traditional MFA solutions face difficulties with their user interface, dependent factors, and doubtful security in the real world despite being generally used. The manuscript details the review of MFA progression, summarizing the central points from four major research papers of Ometov et al. (2018), Li et al. (2021), Wang and Wang (2023), and Paredes-García et al. (2025), correspondingly. The paper highlights the innovation in the Threshold Multi-Factor Authentication (T-MFA), SelfSovereign Identity (SSI), Zero Knowledge Proofs (ZKP), and Shamir’s Secret Sharing (SSS) fields. Besides, it deals with the eight failure categories in formal security proof of MFA, thus, bridging the significant theoretical practical security gap. Research shows that future MFA systems are to be flexible, decentralizedandcryptographicallyverifiablewithfeaturesof privacy and resilience in different real-world scenarios like finance, IoT, healthcare, and cloud infrastructure.
Key Words: Multi-FactorAuthentication,ThresholdMFA, Cryptography, Zero-Knowledge Proof, Secret Sharing, Provable Security, Self-Sovereign Identity, Blockchain, Privacy-Preserving Authentication.
In a hypersensitive world where the digital identity of a person is becoming more and more valuable, the need to securetheaccesstoonlinesystemsisthefirstrequirement. Single-Factor Authentication (SFA) the traditional passwordmechanism hasbeenmostlykeptasamethod becauseofitssimplicitybutpresentssomeseriousrisks.The major problems connected with a single-factor authentication system are password reuse, weak combinations, phishing attacks, and large-scale credential leaksthatallhavedemonstratedthatusingonlyonefactoris notenoughtoprotectmodernsystems

Multi-Factor Authentication (MFA) was introduced as a solutionoflayereddefenseswhichimpliedthatusersmust authenticateviamultipleindependentfactors:
Onethatyouknow–passwords,PINs,oranswersto securityquestions.
Onethatyouhave–smartcards,hardwaretokens, ormobiledevices.
One that you are – biometric or behavioral identifiers such as fingerprints, facial patterns, or voicerecognition.
ThusMFApreventsunauthorizedaccessbyseveralfactors (oneofwhichispresumablycompromised)fromhappening. However, several practical limitations have been revealed duetoitsextensivedeployment:
Rigidity: Traditional MFA necessitates certain combinations (e.g., password + OTP). Users are unable to access their accounts if one factor is missing.
Problems of usability: Users experience inconveniencewithmultipleverificationstepsand therefore,refusetouseMFAfurther.
Security assumptions: Although some "formal proofs"areclaimedbymanysystems,theyignore the impact of the device theft or malware on the securityofthesystem.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
Therecentworksonthresholdcryptography,decentralized identity, and privacy-preserving cryptographic proofs are motivated by a desire to solve the abovementioned problems.ThresholdMFAbasedontheideaofanytoutofn registered factors allows authentication whereas selfsovereign identity (SSI) changes the model of identity management to ensure user control. This paper reviews these innovations and reflects on their possible implementationintheforthcomingdigitalecosystems.
Ometov et al. (2018) conducted one of the earliest comprehensivereviewsofMFA,chartingitsevolutionfrom SFA to Two-Factor (2FA) and ultimately to modern Multi Factor Authentication. Their survey categorized authentication methods into three distinct groups knowledge, possession,andbiometricfactors illustrating how the combination of these factors increases system security. They further evaluated MFA performance using parameterssuchasFalseAcceptRate(FAR)andFalseReject Rate(FRR),whichquantifythetrade-offbetweenusability andsecurity.Ometov’sanalysisalsoemphasizedthatwhile biometric integration improved security, it raised new privacychallenges,especiallywhenbiometrictemplatesare storedoncentralizedservers.Thekeyinsightfromthisstudy isthatMFA’struestrengthliesnotjustinaddingmorefactors butinhoweffectivelythesefactorsareintegrated,managed, andverifiedwithoutcompromisinguserexperience
Li et al. (2021) introduced a groundbreaking concept calledThresholdMulti-FactorAuthentication(T-MFA)which made a significant departure from traditional MFA. Normally, MFA involves a fixed set of factors, but with TMFA,auserisallowedtoverifytheiridentitywithanytout ofnregisteredfactors.Forexample,ifasingleuserhasfive differentauthenticationfactorslikeapassword,smartphone, smartwatch,biometricID,andhomePC,thenthisusercan authenticate with any three (t=3) of these, depending on whichareavailable

Fig -2:Threshold-basedMFAallowinganytofn authenticationfactors.
The T-MFA Key Exchange (T-MFAKE) protocol that they designedlocallycombinesthresholdcryptographywithan ObliviousPseudorandomFunction(TOPRF)tocreatesession keyswithoutdisclosingthefactorsused.Inthisarrangement, thenotionoffactorinvisibilityisintroduced,thus,evenifthe serveriscracked,itcannotinferwhichauthenticationfactors are being used. Additionally, through the use of fuzzy extractors, the protocol changes biometric data into cryptographickeyswhilestillkeepingthedataprivate thus notallowingthebiometricdatatobereconstructedevenif thestorageiscompromised.Theprotocolisefficientenough tocompleteonlytwocommunicationroundswhichisproof of its effectiveness in real-world scenarios. T-MFA is an excellent example of how security, user convenience, and fault tolerance can be harmonized thus; it has solved the issuethatwasthegreatestdrawback ofconventionalMFA systems.
ManyMFAsystemsclaimtobe“formallyprovensecure,” yet they often fail when exposed to real-world threats. In their 2023 study, Wang and Wang analyzed 70 MFA protocolsanduncovered eightmainreasonsbehindthese failures,suchas:
1.Incompletemodelingofadversaries
2.Unrealisticoroversimplifiedthreatassumptions
3.Misuseofcryptographictechniques
4.Ignoringhowauthenticationfactorsinteract
5.Flaweduseoftherandomoraclemodel
6.Poordefenseagainstside-channelattacks
7.Lackofforwardsecrecy
8.Weakorincorrectreductionproofs
Theirresearchshowedthatwhilemanysystemsappear strong on paper, they often overlook practical issues like stolensmartcards,compromiseddevices,orphishing-based breaches.Byidentifyingandclassifyingtheseweaknesses, WangandWangcreatedaframeworktobetterevaluateMFA systemsinamorerealisticway.
Overall, their work highlights the need to balance theoretical security with practical testing ensuring that MFAsolutionsarenotonlymathematicallysoundbutalso resilientintherealworld.
Paredes-García et al. (2025) introduced SIBERIA, a frameworkthatcombinesSelf-SovereignIdentity(SSI)with Multi-FactorAuthentication(MFA)togiveusersfullcontrol over their digital identities. Instead of depending on centralizedidentityproviders,SIBERIAusesdecentralized identifiers(DIDs)andverifiablecredentials(VCs)managed throughblockchaintechnology.Thisensuresthatusersown and manage their identity data directly while keeping it secure and private. The framework supports advanced

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
biometricfactorssuchasvoicerecognitionandbehavioral patterns,aligningwithglobaldataprotectionstandardslike GDPRandeIDAS2.0.Bydecentralizingidentitymanagement, SSIreducesthechancesofmassdatabreachesandbuildsa moretrustworthyauthenticationprocess.
Eachidentityverificationin SIBERIAisrecordedonthe blockchainthroughsmartcontracts,ensuringtransparency, auditability, and privacy. When combined with MFA, SSI createsatrustlessauthenticationsystem,meaningthatno singleauthoritycontrolstheprocess securityisguaranteed bythetechnologyitself
Overall, SIBERIA shows how decentralized identity systems can enhance security in sensitive sectors like industrialoperationsandhealthcare,wherecontinuousand reliableauthenticationisessential.
ModernMulti-FactorAuthentication(MFA)systemsrelyon advanced cryptographic techniques and decentralized architectures to balance security, privacy, and flexibility. Three key technologies Threshold Cryptography, Zero KnowledgeProofs(ZKP),andSelf-SovereignIdentity(SSI) areshapingthenextgenerationofauthenticationsystems.
Thresholdcryptographyenhancessecuritybydividinga secretkeyintomultipleparts(calledshares).Onlyaspecific numberofshares(toutofn)areneededtoreconstructthe secret.ThisideaisbasedonShamir’sSecretSharing(SSS), where:
(0)
Here,f(x)isapolynomialofdegree(t−1),andanytvalid pointscanrecovertheoriginalkeyK.
In MFA, each authentication factor such as a device, biometric,ortoken holdsoneshareofthesecret.Accessis grantedonlywhentherequirednumbersofvalidfactorsare presented.Thismethodprovidestwomajorbenefits:
Fault tolerance: Users can still authenticate even if onefactor(likeadevice)isunavailable.
Resistance to compromise: An attacker cannot reconstruct the secret without collecting enough validshares

Zero-KnowledgeProofsallowonepartytoprovethatthey knowasecretwithoutrevealingthesecretitself.InMFA,this techniqueletstrusteddevicesorusersverifytheiridentity without exposing internal credentials or identifiers. For example,asmartphonecouldproveit’sauthorizedwithout sendingitshardwareIDorcryptographickeytotheserver. This greatly reduces the risk of data leaks and supports compliancewithprivacylawssuchasGDPR.
ZKPscanalsostrengthenthresholdcryptographicsystems byverifyingthateachshareisvalid withoutdisclosingany sensitive information adding an extra layer of trust and transparency.
WhenMFAiscombinedwithSelf-SovereignIdentity(SSI), identitymanagementbecomesfullydecentralized.Insteadof relying on centralized databases, users keep their digital identities in personal wallets, which store verifiable credentials(likecertificatesorlicenses).Thesecredentials canbeindependentlyvalidatedthroughcryptographicproofs andblockchainrecords
SSIensures:
Usercontrol:Individualsdecidewhatdatatoshare andwithwhom.
Cross-platformuse:Thesamecredentialscanbeused securelyacrossmultiplesystems.
Tamper-evidence:Blockchainensuresthatidentity recordscannotbealteredwithoutdetection. This combination of SSI and MFA enables privacy preserving,decentralizedauthenticationecosystems.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
Table -1: ComparativeAnalysisofMulti-FactorAuthenticationResearch
Authors Year Key Contribution
Ometov et al. 2018 Defined MFA evolution and classified authentication factors into knowledge, possession, and biometrics. Introduced comparative metrics like FAR and FRR for usability–security trade-off.
Li et al. 2021 Proposed ThresholdMultiFactor Authentication (T-MFA) and designed TMFAKE protocol integrating threshold cryptographyand ObliviousPRF.
Wang & Wang 2023 Identified eight categories of failures in securityproofsof MFA systems; created framework for analyzing proof soundness.
al. 2025 Developed SIBERIA, a SelfSovereign Identity (SSI)based MFA framework combining verifiable credentials, decentralized identifiers, and
Core Strength Security Approach / Methodology
Comprehensive survey establishing foundational understanding ofMFA.
Analytical literaturereview; factor classification; risk-based discussion.
Evaluation / Findings Limitation
Demonstrated that usability and privacy remain critical trade-offs even in multi-layer authentication. Lacks formal cryptographic modeling and quantitative comparison; focusesmainlyon conceptual discussion.
Highly flexible and efficient; supports authentication with any t of n factors; resistant to server compromise.
Offers a diagnostic foundation for evaluating theoretical security claims; bridges theory andpractice.
Fully decentralized, privacypreserving architecture compliant with GDPR and eIDAS2.0.
Cryptographic design; theoreticalproofs of security; simulation-based performance analysis.
Achieved tworound communication efficiency; demonstrated resistance to replay and factor compromise attacks.
Systematic taxonomy and proof-based analysis; adversarialmodel comparison.
System implementation and case-study validation in industrial environments.
Deployment complexity; computational cost grows with number of registered factors; limited real-world validation.
Highlightedthat many“provably secure” MFA schemes fail in real-world conditions; emphasized stronger adversary modeling. Lacks experimental or prototypetesting; focuses on theoretical vulnerability assessment.
Achieved trustless authentication and continuous verification; strong identity privacy and interoperability.
High computational and storage overhead;latency concerns in blockchain verification; limitedscalability on low-power devices.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
Proposed Integration Insight (Survey Conclusion)
Synthesis of all approaches combining Threshold MFA flexibility, SSI decentralization, and ZKP privacy protection.
5.1
Provides a unified direction for next-generation MFAsystems. Hybrid cryptographic–decentralized designintegrating T-MFA, SSI, and ZKPconcepts. Promises adaptive, privacypreserving, and verifiable authentication for real-world sectors(finance, IoT,healthcare).
Still theoretical; requiresefficient, lightweight cryptographyand cross-domain standardization forscalability.
Multi-Factor Authentication (MFA) is finding use across a wide range of industries, each leveraging its strengths for enhancedsecurityandtrust.
1. BankingandE-Payments:MFAprotectsusersfrom account hijacking by combining device-based verification, biometrics, and transaction-level authenticationtopreventfraud.
2. CloudServices:Itensuressecureaccesstosensitive data by pairing traditional passwords with hardware security keys or behavioral patterns, reducingrisksfromstolencredentials.
3. Healthcare: Patient data is safeguarded using SSI based verifiable credentials and decentralized accesslogs,ensuringprivacyandcompliancewith dataprotectionlaws.
4. IoTDevices:ThresholdMFAspreadsauthentication trustacrossmultipledevices,removingthedanger ofasingle-pointfailureinconnectedenvironments.
5. E-Governance: Governments can use blockchain backed decentralized IDs to enable secure, transparent,andcitizen-controlledauthentication foronlineservices.

Fig -5:MajorapplicationareasofMulti-Factor Authentication.
As digital ecosystems evolve, MFA must adapt to new challenges.Futureresearchisfocusingon:
1. AI-Driven MFA: Building adaptive systems that analyzeuserbehaviorandcontexttoautomatically adjustauthenticationlevelsbasedonrisk.
2. Lightweight Cryptography: Creating efficient cryptographicalgorithmsdesignedforlow-power IoTdeviceswithoutcompromisingsecurity.
3. Post-QuantumSecurity:DevelopingMFAmethods thatremainsecureevenagainstattacksfromfuture quantumcomputers.
4. Cross-DomainInteroperability:Establishingglobal standards to integrate SSI, blockchain, and MFA technologies, ensuring smooth and consistent authenticationacrossplatforms.
Together, these advancements aim to make MFA not only stronger but also smarter, more user-friendly, and better suitedforadecentralizeddigitalfuture
Multi-Factor Authentication has become a key part of modern cybersecurity that has gone through a significant changetohighlysecureframeworksfromstaticpassword systems.InnovationslikeThresholdMFA,Zero-Knowledge Proofs,andSelf-SovereignIdentityhaveopenedthedoorto more intuitive and privacy-respecting MFA solutions. Nevertheless,effortsto makethem scalable,acceptable to users,andefficientintermsofcryptographicoperationsare still ongoing. The future of authentication depends on the creation of adaptive, decentralized, and verifiable identity verificationmethodsthatcanguaranteeusers'securityand offer them convenience. MFA, supported by both cryptographic theory and practical resilience, has the potentialtobecomethecoreofsecureidentitymanagement inthedigitalworld.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 01 | Jan 2026 www.irjet.net p-ISSN: 2395-0072
[1] A. Ometov, S. Bezzateev, N. Mäkitalo, S. Andreev, T. Mikkonen, and Y. Koucheryavy, “Multi-Factor Authentication: ASurvey,”Cryptography, vol.2, no.1, pp.1–31,2018
[2] W. Li, H. Cheng, P. Wang, and K. Liang, “Practical Threshold Multi-Factor Authentication,” IEEE TransactionsonInformationForensicsandSecurity,vol. 16,pp.3573–3588,2021.
[3] Q. Wang and D. Wang, “Understanding Failures in Security Proofs of Multi-Factor Authentication for Mobile Devices,” IEEE Transactions on Information ForensicsandSecurity,vol.18,pp.597–612,2023
[4] D. Paredes-García et al., “SIBERIA: A Self-Sovereign IdentityandMulti-FactorAuthenticationFrameworkfor IndustrialAccess,”AppliedSciences,vol.15,no.8589, pp.1–36,2025
2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008