Abstract
The increasing sophistication of credential theft, phishing attacks and session hijacking has exposed the limitations of conventional password-based authentication systems. Although Multi-Factor Authentication (MFA) enhances account security by requiring additional verification, many existing implementations authenticate users only at the point of login and implicitly trust subsequent activities throughout the session. This approach conflicts with the principles of Zero Trust Architecture, which advocates continuous verification and the elimination of implicit trust. This study presents the design and implementation of a secure login system that integrates Zero Trust Architecture with Time-Based One-Time Password (TOTP) Multi-Factor Authentication to strengthen user authentication and session security. A design-and-implementation research approach was adopted to develop a prototype web-based authentication system using Node.js, Express.js, MariaDB and related security libraries. The proposed system incorporates secure password hashing, QR code-based TOTP enrolment, continuous session validation, device fingerprinting and trust score management to mitigate credential compromise and session hijacking attacks. The system was evaluated using defined security test cases covering user registration, authentication, TOTP verification, session validation and attack simulation. The evaluation demonstrated reliable authentication performance, accurate TOTP verification and effective detection of unauthorised session activity while maintaining acceptable response times for practical deployment. The findings indicate that integrating Zero Trust principles with TOTP-based Multi-Factor Authentication provides stronger protection than traditional password-based authentication by enforcing continuous verification throughout authenticated sessions. The proposed framework offers a practical approach for improving authentication security in modern web applications and contributes to ongoing efforts to strengthen identity protection against evolving cyber threats.
Keywords: Zero Trust Architecture, Multi-Factor Authentication, Time-Based One-Time Password, Authentication Security, Session Management, Web Application Security.
Author(s):
Temidayo Faith Fagbe
Department of Cyber Security, Faculty of Computing,
Air Force Institute of Technology, Kaduna, Nigeria
Corresponding Author Email: faithieeemiii@gmail.com
Kamaludeen Bature Shehu
Department of Cyber Security, Faculty of Computing,
Air Force Institute of Technology, Kaduna, Nigeria
kamalbatureshehu@gmail.com
Samson Adeyinka
Department of Cyber Security, Faculty of Computing,
Air Force Institute of Technology, Kaduna, Nigeria
Samson.adeyinka@afit.edu.ng