
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Prof. Nikita Saindane1 , Pooja Vishwakarma2 , Kalyani Ghodake3, Manish Marndi4
1 Professor, Dept. of Computer Engineering, PHCET, Maharashtra, India 234 UG student, Dept. of Computer Engineering, PHCET, Maharashtra, India
Abstract - With the accelerated development of digital technologies, user authentication has become a crucial requirement for ensuring both security and seamless access in modern web and mobile systems. Conventional authentication, including passwords and fixed credentials, are becoming susceptible to security attacks, such as, data breaches, replay attacks, and identity theft. To overcome these setbacks, this project will suggest a new generation authentication system which incorporates biometric authentication with mammoth cryptographic methods. This system encodes raw biometric data into a secure non- reversible template so that there should never be any sensitive user data stored or sent in plaintext. Moreover, the secure pairing mechanism is also applied to create trusted communication between the user devices and the authentication server. The solution proposed will increase the security level, ensure users privacy and enhance resistance to common attacks by cyber criminals but still be usable. It has been proven through experimental analysis that the system can deliver high authentication throughput with low computation cost and will also be useful in real-world use in security critical systems.
Key Words: Biometrics, Authentication, Passwords, OneTime Passwords (OTPs), SHA-256, Cyber Attacks, Phishing, Identity Theft
Userauthenticationisnowaparamountissuewiththerapid development of online services. Conventional passwordbasedauthenticationmethodsarecommonandmuchsusceptibletohackslikephishingontheinternet,bruteforce andstealingofcredentials.Thereisalsoanadditionalthreat of unauthorized access and identity theft by vulnerable passwordpracticesandpasswordreuse.Inordertoaddress theseshortcomings,currently,authenticationsystemsintegrate passwords with other security appliances like OneTimePasswords(OTPs)andcryptographichashfunctions. Nonetheless, these systems are also dependent on knowledge-based credentials that can be hacked or breached.Thebiometricauthenticationmethodismoresecureasitisbasedonthepersonalcharacteristicsoftheuser, however, it also has its privacy and security problems in termsofbiometricdatastorage.Thisprojectisfocusedon thenextgenerationauthenticationsystemandinvolvesthe applicationofbiometricscombinedwiththeuseofsafecryptographysystemstoenhancesecuritywithoutviolatinguser
privacy.Theproposedsystemcanprovideenhancedsecurity tocyber-attacksandthevalidityofidentityverification.The currentprojectisdevotedtothenext-generationauthentication process that consists of a highlysecure cryptography system and biometrics to enhance the security level and avoidanyinvasionoftheuserprivacy.Theproposedsystem canenhanceitsabilitytochecktheidentityanditsabilityto with-standcyber-attacks.

Thetraditionalprocessofuserauthenticationhasbeenwith thehelpofusingpasswords.Password-basedsystemshave beenfoundwantingoveryearsduetoincreasingcomplexity ofcyber-attacks,includingphishing,keyloggingandbruteforce attacks. Despite other security mechanisms such as hashed passwords and the use of One Time Password (OTPs),hackersstillfindexploitationinthevulnerabilityof thesystemandhumanfactor.Biometricauthenticationsystemsarenowinwidespreadusesuchasfingerprintandfacialrecognition,toenhancesecurityverification.Inspiteofthe fact that biometrics are more reliable because of their uniqueness,privacyissues,dataleaksandirremovablebiometricwelfarearechallenges.Asaresultofsuchlimitations, advanced authentication systems that offer solid cryptographicaltechnologyandbiometricsarecurrentlyneededin anattempttoguaranteehighsecurityandprivacyoftheusers.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
The rise in the rate of cyber-attacks and cases of identity thefthasgreaterawarenessoftheinadequacyofoldtraditionalauthenticationsystemsusingpasswords.Weakpasswordsarefrequentlyreusedbytheusersandtheyareeasy targets of phishing and credential thefts. Even such improvedtechniqueslikeOTPsandhashedpasswordscannot stopadvancedattackscompletely.Biometricauthentication ismoresecurethoughitalsoraisessomeissuesregarding privacyandstorageofbiometricdatainasafemanner.Theseissuesinfluencedthecreationofanewgenerationauthenticationsystemthatintegratesbiometricswithcryptographictoimprovesecurityandatthesametimeprovidesuser privacy,aswellasminimizetheuseofpasswords.
Themainobjectiveofthisprojectistoprovidearobustauthenticationmechanismbyintegratingbiometricverification withcryptographicsecuritymethods.
Literature Review of the research papers:
1. Random Hash Code Generation for Cancelable Fingerprint Templates using Vector Permutation and Shift-order Process:
Intheirstudy,S.M.AbdullahiandS.Sunpresentamethod forprotectingfingerprinttemplatesthroughthegenerationofrandomhashcodesusingvectorpermutationcombined witha shift-ordertransformation process[1].The proposedtechniquefocusesonimprovingthesecurityof biometric systems by generating cancelable fingerprint templatesinsteadofstoringoriginalbiometricdata.Inthis method,fingerprintfeaturesaretransformedintorandomizedhashvalues,makingitdifficulttorecovertheoriginal biometric information from the stored templates and therebyenhancingdataconfidentiality.
Advantages: Theproposedarchitectureenhancestheprotectionofbiometricdatabecauseoftheabsenceofthenecessitytostorerawfingerprintdata.Also,themechanism oftransformationallowsthecreationofnewtemplatesin caseatemplatehasbeenstoredinthesystempreviously, whichenhancestheprivacyoftheuserandtheflexibilityof thesystems.
Limitations: Themethodhasseveraldrawbacksdespitethe benefitsofsecuritysinceitaddsextraprocessingoverhead byincludingseveralstepsoftransformationingenerating templatesandinmatchingthem.Besides,themethodology primarily focuses on securing biometric templates and
lacksthemechanismsoftime-basedauthenticationorsuppressingreplayattacks.
2. A Cancelable Templates for Secure Face Verification based on Deep Learning and Random Projections:
InthestudyconductedbyA.Alietal.,aprivacy-preserving faceverificationmethodisintroducedthatcombinesdeep learningtechniqueswithrandomprojectionmechanismsto generatecancelablebiometrictemplates[2].Theproposed approachextractsdeepfacialfeaturerepresentationsand transformsthemintoprotectedtemplatesthroughrandom projection operations. This transformation makes noninvertible representations, assuring that the templates storedcannotbeusedtoreconstructtheoriginalfacialimages.Asaresult,themethodsignificantlyincreasesthesafeguarding of the biometric information even in situations wherestoreddatacouldbecompromised.Advantages:The frameworkincreasessecurityofFace-basedauthentication systemsbyeliminatingtheneedtostoreunprocessedbiometricfeatures.Theintegrationofdeeplearningcontributes toimprovedfeatureextractionandrecognitionperformance –Randomprojectionprovidestemplaterevocabilityanduserprivacybyproducingtransformed,cancellablerepresentations. Limitations: The dependence on deep neural networkmodelsincreasesthecomputationalrequirementsand may require higher processing power. Furthermore, the proposedmethodmainlydealswithfaceverificationsecurityanddoesnotaccountforanyotherauthenticationlayers likemulti-factorauthenticationortime-basedauthenticationmechanisms.
3. A New Fuzzy Vault based Biometric System Robust to Brute-Force Attack:
Intheirwork,A.F.DeAbiega-Leglisseetal.presentabiometricauthenticationframeworkbasedonthefuzzyvault cryptographic scheme to make it more resistant to bruteforce attacks [3]. The proposed method for securing biometricinformationbylinkingbiometricfeatureswithcryptographickeysina fuzzy vaultstructure.This designconcealsthetruebiometricdatawithinmanychaffpointsmakingitextremelydifficultforanattackertoretrievemeaningful information even though the vault data is exposed. By combiningcryptographicprotectionwithbiometricauthentication:thesystemseekstostrengthenthesecurityofbiometricstorageandverification(Overall)processes.
Advantages: Theapproachimprovesbiometricprotectionby combiningcryptographickeybindingwithbiometriccharacteristics. The construction of the fuzzy vault increases resistanceagainstbruteforceattemptsandpreventdirectexposureoforiginalbiometricinformationstoredinthesystem.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Limitations: Although the technique requires complicated proceduresforvaultgenerationanddecoding,whichcould yieldanincreasedcomputationaloverhead.Inaddition,differencesinthequalityofbiometricinputdatacanimpacton thereliabilityoftheunlockingprocess.Possiblydecreasing theaccuracyofauthentication.
4. Cancelable Biometric Template Generation Using Random Feature Vector Transformations:
Inthisstudy,R.S.P.Ragendhuetal.proposeatechniquefor developmentofcancelablebiometrictemplatesviatheapplicationofrandomfeaturevectortransformationmethods [4].Thekeyconceptoftheapproachistoprotectbiometric informationbyconvertingextractedbiometricfeaturesinto transformedrepresentationsthatcannotbereversedtoget theoriginal data.Bygeneratingsuch protected templates, the system ensures that biometric credentials can be revokedandreplacediftemplateiscompromised,whilststill supportingdependableauthenticationperformance
Advantages:Theproposedmethodenhancestheprivacyof biometricsystems–byavoidingthestorageofrawbiometric characteristics.Theuseofrandomfeaturetransformations permitsthecreationofrevocabletemplates,whichreduces the likelihood of misuse of biometric data and enhances overallsecurity.
Limitations: Transformedoperationsmayincreasecomputationaldemandsatthetimeoftemplategenerationandverification.Furthermore,authenticationperformancemightdecline if the transformed feature space is not carefully designed/optimized,whichmayaffectrecognitionaccuracy
Toenhancesecurityandprotectuseridentitiesinonlineapplicationsandanumberofstudieshaveconcentratedonimprovingdigitalauthenticationsystems.Themajorityofexistingsolutionsusepassword-basedauthentication,whichis oftencombinedwithcryptographichashingtechniquesand One-time Password (OTP) to avoid unwanted access. According to research, while these techniques provide some protection,theyarestillnotsafefromidentityfraud,phishingattacks,andtheftofcredentialsduetohumanerrorand credentialreuse.Althoughsomeresearchhaslookedintousing biometric authentication to enhance identity verify, problemsofsafestoringbiometricdata,privacyconcerns, andirrecoverabledatacompromisestillexist.Thesedrawbacksillustratethatinordertosuccessfullycombatcurrent
cyberthreats;currentauthenticationsystemsneedmoresecureandmoreprivacy-preservingstrategies.
Passwords and OTPs, which are the major constituents of currentauthenticationsystems,areextremelyvulnerableto onlinethreatssuchasphishing,identityfraudandcredentialstheft.Systemsecurityisfurthercompromisedbyweak password practices and password reuse, which is still exploitedbyattackers.Impropermanagementandstorageof biometric data is coming with great privacy and security concerns, even though biometric authentication provides morepowerfulidentityauthentication.Therefore,toensure useridentityprotectionandpreventunwantedaccess,nextgenerationauthenticationsystemthatsafelyintegratesthe biometricsandcryptographictechniquesisrequired.
Toovercomethesecurityandusabilityissueswithstandard passwordandmechanismbasedonOTP,theproposedsystemprovidesadynamicauthenticationapproach.Basedon timereliantcredentialgeneration,cryptographickeybinding,cancellablebiometrictemplate,thesystemoffersasafe authenticationprocessinadditiontoensuringthatunprocessed biometric in this way data is never therefore revealed.Someoftheweaknessesoftraditionalauthentication systemssuchaspasswordreuse,phishingattacks,replayattacksandinthiscaseirreversibleleakageofbiometrics.The proposedsystemdesigneliminatestheseproblemsbyensuring that authentication credentials are dynamic, nonreusableandrevocable.
Theauthenticationworkflowisdividedintofourmainphases:
1. Userregistration
2. Devicepairing
3. Loginandauthentication
Eachphaseperformsaspecificfunctiontoensuretheintegrityandconfidentialityoftheoverallauthenticationmechanism.
7.1. Phase of registration (Generation of Cancelable Biometric Templates)
Theprocessofregistrationiswhentheuserisenrolledinto thesysteminasecureandprivatemanner.Inthisstep,the usergetstotypeinaspecificidentifier,andhis/herbiologi-

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
calfingerprintisscannedwithabiometricsensor. Thefingerprintcapturedishandledbythebiometricinfrastructure andtransformedintoastandardANSIfingerprinttemplate whichisnormallyheldintheformofabytearrayinternally.
Theformatisstandard,whichmeansthatthesystemisnot reliantonaparticularfingerprintsensor.Thefirststepofthe systemisacancellabletransformationthatensuresthatthis originalbiometricdatacanneverbere-obtainedpriortothis fingerprinttemplatebeingdirectlystored.Toachievethis,a shuffleseedisgeneratedwiththehelpoftheSHA-256hash function.Theidentifierusedbytheuserissitespecificsalt andthepublickeyofthemobiledeviceandtheidentifieris usedtogeneratethehash.Suchacombinationofthesame fingerprintwillgivedifferenttemplatesdespitethepossibilityofusingthesamefingerprintonadifferentplatformor device.Basedonthegeneratedhashvalue,apseudo-random numbergenerator(PRNG)issetup.ThisPermutationofthe template indices in a pre-determined way. Permutation is usedtorandomizethefingerprinttemplate,whichremoves thenativespatialorganizationofthefingerprintandmakes itdifficulttorecreatethefamiliarbiometricprint.
Tocreateamoretolerantsystemastominordifferencescertainvariationsduringfingerprintcapture,theshuffledtemplateissplitintoanumberoffixed-sizepieces.Eachsegment hasrepresentativefeatureswhicharecomputedbysimple algorithmssuchastakingthehighestvalueorcomputinga checksum.Thesevaluesextractedarethenpooledwitheach othertocreateafixedlengthfeaturevector.
Thelaststepistheencodingofthisfeaturevectorusingthe Base64encodingalgorithmtoformthecancellablebiometric template,denotedCTweb. Theresultanttemplatecansupport secure authentications and cryptographic functions sinceonceithasbeencreated;onecannolongerreverseit toextracttheoriginalfingerprintandcanberepairedincase requirementschange.
Thestageofdevicepairing withthedeviceauthentication decidesasecureconnectionbetweenthemobileauthenticationdeviceoftheuserandthewebapplication.Thissystem adds a CT_web and minimum information on servicesrelateddataintoaQRcodeupongeneratingthecancellable template.Thefirsttimetheusergoesthroughthesetupprocess,theQRcodeisdisplayedtotheuser.Theuserusesthe mobileauthenticationapplicationtoreadtheQRcodeand thepairingprotocolisactivated.Inthisprocess,themobile devicetransmitstheserverthepublickeyandcreatesorob-
tains its asymmetric key pair. The server then encrypts CT_web withthispublickey anditsendsencrypted informationbacktothemobileapplication.
The encrypted template can only be decrypted within the paireddevicebecauseithasthecorrespondingprivatekey. Thestepensuresthatauthenticationcredentialscannotbe copiedorusedonothernotauthorizeddevices.Afterbeing decrypted,thetemplateisstoredsafelyinthemobileapplication,andthisprocesshasbeenpaired.
Authenticationisdoneatthestageoflogginginwithoutthe userbeingrequiredtorecallanduseaconstantpassword. Theuserlogsintothemobileapplicationandhis/herlocal fingerprintverificationaredone.Thison-siteauthentication helpstoascertainthatbiometricmatchingisdonefullyon thetrusteddevice.
The mobile application creates a dynamic authentication passwordbasedonthesuccessfulverificationwiththehash function which is the hash-256. The cancellable biometric template, the current time-stamp and the salt that is sitespecificareallthatisinputtedintothehashfunction. The authentication credential generated is a short-lived value basedonthetruncatedhashvaluetoanalphanumericformat.
Thewebapplicationtakesthegenerateddynamicpassword, andtheserverdeterminestheexpectedvalueseparatelyby use of the same parameters. Authentication will only be granted on submission and calculation of values that are equalandthetimefallswithinthestipulatedtime.Thisdesign ensures that each authentication attempt is one-time andcanneverbeduplicated.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

The methodology of this work is aimed at developing and testingofthesecureauthenticationsystemthatwouldexclude the OTP-based verification and unchangeable passwords.Thesuggestedapproachwillenhancethelevelofsecurity,atthesametimeconsideringtheapplicationspecific usabilityandpracticality.Thedevelopmentprocesshadseveralstages.Itstartedonmakingsystemrequirements,system design, implementation of biometric processing techniquesandlastly,byevaluatingthesecurityoftheproposed system.
1. RequirementIdentification:
Thefirststageinvolvedanalyzingcommonlyusedauthenticationmechanismsandidentifyingtheirlimitations. Even thoughpassword-basedauthenticationsystemsarewidely used,theyarevulnerabletophishingattacks,reuseofpasswords,anduseofweakpasswords.OTP-basedsystemsenhancesecurity,buthavedelaysanddependonthird-party communicationsystemssuchasSMSoremail.Biometricauthenticationisverysecure,butitmaybeamatterofconcern to store raw biometric data indefinitely, as doing so may compromise the privacy of the users. These observations wereusedindefiningtherequirementsofthesystem.The systemmustnotbereusableofcredentials;itmustalsosecurebiometricdataandmustbeeasytousebytheuser. The
otherrequirementwastheabilitytorevokeandreissueauthenticationcredentialsincaseofacompromise.
2. MethodologyforSystemDesign:
Theoverallarchitectureofthesystemwasdevelopedfollowingthedefinitionoftherequirements.Amobilebasedauthentication model was selected to enable the biometric verificationtobeperformedontheuserdevice.Thismethod willdecreasethevulnerabilityofbiometricinformationand restrictthesizeofsensitivedatastoredintheserver.
Someoftheindependentmodulesofthesystemwerebiometricprocessing,devicepairingandauthenticationverification.Thismodulardesignallowsonetoeasilymanagethe systemandbeabletomodifyorenhanceaparticularcomponentwithouthavinganyeffectonthewholesystem.
Theuseoffingerprintbiometricswaschosenduetoitsabilitytohaveauniversalapplicationinmodernhardwareand theabilitytoofferhigh-qualityidentification. Whenthefingerprintisregistered,astandardANSIfingerprinttemplate is created through transformation of the captured fingerprintimage.Thiswillensurethatdifferentfingerprintsensorsarecompatible.Theoriginaltemplateisnotstoredbuta cancellabletransformationmethodisapplied.Withuserand devicespecificparametersacryptographichashisgenerated,andthevaluelimitstheprocessofshufflingofthetemplates.Inturn,thestructureoftheoriginalfingerprintisdistortedbythemodifiedtemplate.Ashuffledtemplateisdividedintosmallerpiecestoensurethatitismademoreuniform.Eachsegmentgeneratesrepresentativefeatureswhich arejoinedtocreateafixedlengthrepresentation. Thislast representation is the cancellable biometric template on whichauthenticationisdone.
Whenthebiometrictemplateiscreated,itshouldbesecured tothemobiledeviceoftheuser.Thisisdoneinthefirststage ofregistrationwhereinapairingsystemisappliedusinga QRcode.Thebiometrictemplatewouldbescannedbythe mobileapplicationcodedinaQRcode.Asymmetricencryptionisusedtoprotectthedatawhichisbeingtransmitted. Themobileapplicationwilldecrypttheencrypteddatawith theassociatedprivatekeyandthetemplatewillbeencryptedwiththepublickeyofthemobiledevice. Thiswillensure that the authentication credentials are never related with morethanonetrusteddevice.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
5. AuthenticationandLoginProcess:
Thereisminimalinteractionoftheuserwiththemobileapplicationexceptwhenitcomestologgingin.Theapplication willfirstdolocalfingerprintverificationinordertoverify theuser.Adynamicpasswordisgeneratedafterthesuccessfulverificationisrealizedusingacryptographichashfunction.Passwordisthecombinationofcancellablebiometric template,up-to-datetimeandsite-specificparameter. The passwordistimedependent,meaningthatitisnotvalidover alongperiodoftime.
Thepasswordgeneratedisthengiventothewebserverto beverified. Theserverdeterminestheexpectedvalueindependentlyandcomparesitwiththereceivedpassword.In casethevaluesareidentifiedasbeingthesamewithinthe giventimeslot,accessisprovided.
6. SecurityAssessment:
Theproposedsystemwasevaluatedagainstseveralcommon security threats. Phishing attacks, replay attacks, and the unauthorizedreuseofcredentialsareexamplesofthese.Alsolookedatwerescenariosinvolvinginterceptedauthenticationdata.Becausethesystemdoesnotstorerawbiometric data,theriskofbiometricinformationleakageissignificantlyreduced.Additionally,theuseofcancellablebiometricsthismeansthatnewtemplatescanbegeneratedifneeded, ensuringthatcompromisedcredentialscanbechanged.
9 ALGORITHMIC REPRESENTATION
Algorithm1:CancellableBiometricTemplateGeneration
Input: Fingerprint F,UserID UID,SiteSalt S,DevicePublic
Key PK
Output: CancellableTemplate CT_web
1. Convertthefingerprint F toANSItemplate T
2. Compute Seed = SHA-256(UID | S | PK)
3. InitializePRNGusing Seed
4. Generatepermutation P
5. Applypermutation P totemplate T toget Tshuffled
6. Split Tshuffled intofixed-sizesegments
7. Extractstablebiometricfeaturesofeachsegment
8. Combineextractedfeaturesintofeaturevector V
9. Encode V usingBase64toget CT_web
10. Return CT_web
Algorithm2:SecureDevicePairing
Input:CancellableTemplate CT_web
Output:Securelystoredtemplateonmobiledevice
1. Encode CT_web intoaQRcode
2. ScantheQRcodeusingthemobileapplication
3. MobiledevicesendspublickeyPKtotheserver
4. ServerencryptsCT_webusingthereceivedpublic keyPK
5. Forwardtheencryptedtemplatetothemobiledevice
6. Mobiledevicedecryptsthetemplate,usingitsprivatekey
7. Keepthedecryptedtemplatesecurelyonthemobile device
Algorithm3:DynamicAuthenticationProcess
Input:CancellableTemplate CT_web,Timestamp T,Site Salt S
Output: AuthenticationResult
1. Computedynamicpassword
DP = Truncate (SHA-256(CT_web | T | S))
2. Submit DP totheauthenticationserver
3. Servercalculatesexpecteddynamicpassword
DP_server
4. If DP = DP_serverandtimestamp T isbetweenthe validtimewindow
Grantauthenticationaccess
5. Else
Rejectauthenticationrequest
9. SECURITY ANALYSIS
A.DynamicCredentialGeneration
In the authentication process, the system calculates a dynamicpassword(DP)basedonthebiometrictemplatethat canbecancelledandtime-basedparameters.
Letthecancellablebiometrictemplatecreatedatthetimeof enrolmentbeindicatedasCT.Thedynamiccredentialiscalculatedusingacryptographichashfunction:
DP = Truncate(SHA-256(CT ∥ Ts ∥ S))
Where,
CT isthecancelablebiometrictemplate, Ts isthecurrenttimestamp,

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
S containsasystemspecificsaltvalue.
Sincethetimestampisconstantlychanging,thegenerated credentialbecomesuniqueforeachauthenticationsession and remains valid only within a predetermined time window,whichgreatlyreducesthelikelihoodofcredentialreuse.
Thesystemusesatransformationfunctiontocreateacancelabletemplateinplaceofstoringrawbiometricdata:
CT = T (B , s)
Where,
s isatransformationseed,
B istheextractedbiometricfeaturevector.Thisprocedure guaranteesthattheoriginalbiometricdatacannotberecoveredbyreversingthestoredtemplate.Thisfeatureofferstemplaterevocability,whichisasignificantdrawback intraditionalbiometricsystems.
Intheeventofapossiblecompromise,anewtemplatecan becreatedusingadifferenttransformationseed:
CT’ = T (B , s’)
Thisapproachenhancesthesecurityoftheauthentication system,itensuresthateveniftransformedtemplateisexposed,itisnotreusableorlinkedtotheoriginalbiometric data.
Asaresult,thissystemmaintainsbothprivacyandsecuritywhilealsosupportingauthenticationofusersinasecuredlockedsystem.
Attack Resistance Analysis
Attack Type Password-Based System OTP-BasedSystem Proposed NextGen System
Phishing Attack Highriskdueto credentialexposure
Moderateriskif OTPintercepted Resistant dueto biometric verification
Replay Attack
Possibleifcredentialscaptured
Brute ForceAttack
CredentialTheft
Possiblewithin OTPvalidity window Prevented bytimebased dynamic password
Possiblewith weakpasswords Limitedprotection Extremely difficult dueto hashbased credentialgeneration
Passwordleakagepossible OTPinterceptionpossible
Device Impersonation
Possiblefromany device
Noreusable credentials available
PossibleifOTP accessed Prevented through secure device pairing
Withtheeliminationofthestagnantorreusablecredentials thatareactivelyusedintraditionalpasswordandOTP-based systems,theproposedNext-Genauthenticationframework improvessecurity.
Alternatively,authenticationisperformedusingcancelable biometrictemplatesandtime-sensitivedynamicallygeneratedcredentialsbyusingcryptographichashfunctions.This strategyreducesthechancesofreplayattacksandtheuseof credentials since each authentication value can be unique andonlylastforagiventime.
Besidesthat,thedevicepairingmechanismalsolimitsunauthorizedaccesstodevicesunlesstheiraccountinformation is exposed, by enabling the authentication of only a registeredmobiledevice.
The proposed system's resistance to common security attacks is compared to that of conventional authentication methodsinTable1.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Thesuggestedsystem'ssecurityfeatureswerealsocontrastedwithother conventional authenticationmethods. The proposedframeworkcombinesseveralsecurityfeaturesthat together lowertheattack surface and improveauthenticationreliability.
cation
Credential
bility
Thefirststepsoftheauthenticationprocedurearefingerprintcollectionandobtainingthebiometricfeatures.Anencryptedcopyofthefeaturesextractedisstoredinacancellabletemplateonthecorrespondingmobiledevice,whichis safe.
Ahashfunctionandparameterofatimestampareused
togenerateadynamicpasswordduringloginusingthetemplate.Thegeneratedcredential isforwardedtotheserver beforeaccessisgrantedandthecredentialisauthenticated withinastipulatedtime.
The multi-stage startup of the authentication process enhancestheresistancetocommonauthenticationattacksby makingtheauthenticationcredentialsbothtime-dependent anddevice-boundandinapplicable.

Computationalefficiency,authenticationlatencyandsystem overhead of the proposed next generation authentication framework were investigated when using a login process. Authenticationalgorithmcomprisestheoperationsofbiometric feature extraction, cancelable template transformation,dynamicallygeneratedpasswordbycryptographic hashgeneration,andservervalidation. Eachofthesestages affectstheoveralltimeandmoneyusedinthecomputation oftheauthenticationprocess.Thesuggestedapproachdoes notrequireanyexternalcredentialdeliveryproceduressuch asSMSoremailascomparedtotraditionalauthentication protocolssuchaspassword-basedand
OTP-basedauthentication.Ratherthanthat,thecancelable biometrictemplatealongwithtime-sensitiveparametersis storedandusedtoformadynamicpasswordonthepaired mobiledevice.Thisminimizesthedependencyonanetwork andenhancesthespeedofauthenticationaswellasensuring highlevelofsecurity.
Threeevaluationaspects-thecomparisonofauthentication time,thecomparisonofcomputationalcost,andthedistributionofsystemoverhead-wereexaminedinordertogaina deepercomprehensionofthesystem'sperformancecharacteristics.Thefiguresthatfollowprovideanillustrationofthe outcomes.

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
A.AuthenticationTimeComparison:
ThisgraphcomparestheaveragetimeofauthenticationrequirebytheproposedNextGenauthenticationsystem,OTPbasedauthenticationandtheconventionalpassword-based authentication.AlthoughusingOTPbasedsystemsincreases moredelaysthroughnetworktransmissionandmessagedelivery,password-basedauthenticationnormallyconsistsof small processing time throughcredential verification. The proposedsolution,incontrast,generatesadvantageouscredentials locally on the connected device significantly decreasingtheauthenticationlatency,preservingstrongsecuritycontrols.

B.ComputationalCostComparison:
Thischartgivestherelativecomputationcostofdifferentauthenticationmethodsatdifferentoperatingphases.Whereas OTP-likesystemsintroduceanadditionalnetworkcost,traditionalpasswordsystemsusemostlystaticcredentialsand requireverylittlecomputation.Duetoitsefficientauthentication procedures and Cryptography hashing lightweight, theproposedauthenticationsystemsupportsthebiometric processingandlowcomputationcomplexity.Greatersecurityistherebyachievedbythesystemwithoutstrainingcomputingcosttothesystem.

Authentication Latency Table
D.SystemOverheadDistribution:
Thepiechartpresentsthedistributionofthecomputational loadbetweenthedifferentstagesoftheproposed authentication process. Biometric feature extraction takes the largest candidates of processing costs since it needsthegatheringandaddressoffingerprintdatasoasto offeraconsistentfeaturerepresentation.Theleftoveroverheadisfurtherdividedintoserver-sidevalidation,hashingbaseddynamicsortingofpasswordsandtemplatecustomization.Theoverallsystemoverheadisatbalancedleveland suitableinrealtimeauthenticationwherethereisanadditionalbiometricprocessingstep

Research
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

ComparedtothetraditionalOTP-basedauthenticationsystems, the proposed authentication framework can reduce networkdependencetoasignificantdegree.TraditionalOTP authenticationwillrequireexternalcommunicationservices suchasemaildeliveryservicesorSMSdeliveryservicesand thiswillintroducelatencyandmayfailwhennetworkconnectivityislow.Conversely,theproposedapproachconsidersparametersbasedontimeandthetemplateofcancellablebiometricstogeneratedynamicauthenticationcredentialsatthelocallevelsoftheconnectedmobiledevice.This approachwillensurefasterauthenticationevenwithinlimited network environments andeliminate thedelayinthe deliveryofmessages.
Thesysteminquestionis,intermsofscalability,sufficientto split computational workload between the authentication serverandaclientdevice.Lightweighthashverificationand timestampvalidationareonlydonebytheserver,themobile devicelocallygeneratesthedynamicpassword.
Theauthenticationservercanalsoacceptanumberofsimultaneous authenticationrequestswithouta noticeableperformancedegradationastheseprocessesneednotdemand muchprocessingunits.Thisdesignallowstheproposedauthentication system to be deployed in large-scale applications such as financial applications, business applications andlearningsystems.

Theforegoingfigureshowstheprocessofregisteringwith theuserhavingausernameandfingerprintinputwithwhich theusergainsbiometricenrollment.
Step2.

Thisfigureindicatesthatthefingerprintisscannedthriceto comeupwithastableanddependable biometrictemplate thatonecanbeauthenticatedagainst.
Step3:


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
ThefiguredepictsthecreationofQRcodethatisusedtosecurelylinktheuser’smobiledevicewiththewebapplication
Step4:

Fig -7:MobileApplicationDetectingLinkedAccount
Thefigureaboveindicatesthattheregisteredaccountof theuserisdetectedbythemobileapplicationandreadyto createasecuredeviceconnection.
Step5:

Fig -7:QRCodeScanningforSecureConnection
Thisfiguredemonstratesthatthemobileapplicationis scanningtheQRcodeestablishingasecureconnection withthewebserver.
Step6:

Fig -7:SecureStorageofEncryptedBiometricTemplate
Theabovefiguredepictstheencryptedbiometrictemplate beingsecurelystoredontheuser’smobiledevicetopreventunauthorizedaccess.
Step7:

Fig -8:UserLoginwithDynamicPassword
Thefigureabovedepictsthelog-inproceduretotheuserinvolvingenteringtheemailanddynamicallygeneratedpasswordofthemobileapplication.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Step8:

Fig -9:SuccessfulAuthenticationVerification
Herethefiguredepictsthatauthenticationsucceededfollowingdynamicpasswordvalidationonclientaswellasserver side.
The constraints of the conventional password and OTPbasedauthenticationtoolswereovercomebycreatingasecureauthenticationsysteminthisproject.Thecurrentsystems have frequently been associated with security problemsthatincludethereuseofpasswords,phishingattacks, andtheoccurrenceofdataleakages,therefore,drivingthe desiretoestablishasuperiorsolution.
Thesuggestedsystemappliestheapplicationsofbiometric datainaprivacy-savingmanneroftransformationinaformatofacancellableandirreversibledataformat.Rawbiometricinformationisnotatanypointstoredortransmitted, whichisanaddedsecuritytouseridentity.Securityisalso enhanced by the device bonding and time authentication whichmakessurethatthesetofthelogincredentialscannot bereusedorabused.
Ingeneral,thesystemshowsthatthestrongauthentication maybeimplementedwithouttheuserfacingthecomplexity increment.Themethodisfeasible,safe,andcanbeappliedin thefieldswherethehighlevelofreliabilityandsecurityis neededlikeinabankingsystemsandeducationalplatforms.
ItisaprivilegeforustohavebeenassociatedwithProf.NikitaSaindaneourguide,duringthisprojectwork.Wehave
greatlybenefitedfromhervaluablesuggestionsandideas.It is with great pleasure that we express our deep sense of gratitudetothemfortheirvaluableguidance,constantencouragement,andpatiencethroughoutthiswork.Wearealsoindebtedtoourguideforextendingthehelptoacademic literature.WewouldalsoliketoacknowledgeRyanGosling asasourceofinspirationandmotivation.
[1] S.K.Sahoo,S.C.Das,andS.Bakshi,“RandomHashCode GenerationforCancellableFingerprintTemplates,”IEEE TransactionsonInformationForensicsandSecurity,vol. 20, no. 5, pp. 567–576, May 2025, DOI: 10.1109/TIFS.2025.3399874.
[2] M.Gomez-BarreroJ.Fierrez,andJ.Galbally,“Cancelable Template for Secure Face Verification Based on Deep LearningandRandomProjections,”IEEETransactions onInformationForensicsandSecurity,vol. 13,no.11, pp. 2747–2762, Nov 2018, DOI: 10.1109/TIFS.2018.2833040.
[3] P.Drozdowski,C.Rathgeb,C.Busch,andA.Uhl,“OTBMorph:One-TimeBiometricsviaMorphing,”inProceedingsofthe2023InternationalConferenceonBiometrics (ICB), Crete, Greece, 2023, pp. 1–8, DOI: 10.1109/ICB57460.2023.10199205
[4] A.JuelsandM. Sudan, “ANewFuzzy VaultBasedBiometricSystemRobusttoBrute-ForceAttack,”Designs, Codes and Cryptography, vol. 38, no. 2, pp. 237–257, Feb.2006,DOI:10.1007/s10623-005-6343-z.
[5] M El-Abed,M.Gomez-Barrero,andJ.Fierrez,“CancelableMultimodalBiometricsBasedonChaoticMaps,”PatternRecognitionLetters,vol.165,pp.57–65,Apr.2023, DOI: 10.1016/j.patrec.2 023.01.009.M. El-Abed, M. Gomez-Barrero,andJ.Fierrez,“CancelableMultimodal BiometricsBasedonChaoticMaps,”PatternRecognition Letters, vol. 165, pp. 57–65, Apr. 2023, DOI: 10.1016/j.patrec.2023.01.009.
[6] A.KumarandD.Zhang,“CancelablePalmprint:Intelligent Framework Toward Secure and Privacy-Aware Recognition System,” IEEE Transactions on Systems, Man,andCybernetics:Systems,vol.54,no.3,pp.1182–1195,Mar.2024,DOI:10.1109/TSMC.2024.3345612.
[7] A. K. Jain, K. Nandakumar, and A. Nagar, “Biometric Template Security,” EURASIP Journal on Advances in SignalProcessing,vol.2008,no.1,pp.1–17,Jan.2008, DOI:10.1155/2008/579416.
[8] R.Cappelli,D.Maio,A.Lumini,andD.Maltoni,“FingerprintImageReconstructionfromStandardTemplates,” IEEETransactionsonPatternAnalysisandMachineIntelligence,vol.29,no.9,pp.1489–1503,Sep.2007,DOI: 10.1109/TPAMI.2007.1097.
[9] M.Gomez-Barrero,J.Galbally,J.Fierrez,andJ.OrtegaGarcia,“CancelableBiometrics:AComprehensiveSurvey,”PatternRecognition,vol.82,pp.93–105,Oct.2018, DOI:10.1016/j.patcog.2018.04.023
[10] S.Rane,Y.Wang,S.C.Draper,andP.Ishwar,“SecureBiometrics: Concepts, Authentication Architectures, and Challenges,”IEEE Signal ProcessingMagazine,vol.30, no. 5, pp. 51–64, Sep. 2013, DOI: 10.1109/MSP.2013.2266951.