Skip to content
Open access

LegacyVault: A Secure Web-Based Digital Will Management System with Multi-Party Verification and Behavioral Monitoring

2026 · International Journal Of Engineering And Computer Science · Vol 15, pp. 28820-28832 · 0 citations

TL;DR

LegacyVault is a web-based digital will management system that integrates authentication with password hashing, AES document encryption, rule-based behavioral risk scoring, inactivity detection, and comprehensive audit logging within a single lightweight system.

Abstract

The increasing digitization of personal and legal records has created demand for secure platforms that can store sensitive testamentary documents and manage their transfer after an owner's death or prolonged incapacity. Existing consumer tools, such as platform-specific legacy-contact features, and academic proposals such as blockchain-based inheritance systems, address parts of this problem but not the combination of behavioral monitoring, inactivity-triggered access, and distributed, multi-party authorization within a single lightweight system. This paper presents LegacyVault, a web-based digital will management system that integrates authentication with password hashing, AES document encryption, rule-based behavioral risk scoring, inactivity detection, a multi-party verification mechanism requiring at least two independent approvals for emergency access, and comprehensive audit logging. The system was developed using a prototyping methodology and evaluated through functional, usability, and security testing on a working prototype. Test results show that authentication, document encryption, trusted-contact assignment, inactivity detection, and audit logging modules operated as designed, with average operation response times between 1.2 and 7.0 seconds. We discuss how these results compare with existing platform-specific and academic approaches, note the limitations of the small-scale prototype evaluation, and outline directions for scaling the system toward real-world deployment.

Read PDF

Similar papers

Open access Aug 2026

Development and Evaluation of an Authentication-Based Access Control Framework for Secure Web-Based Ebook Distribution

The increasing use of digital learning resources has created a growing demand for secure ebook distribution systems. However, many existing ebook platforms remain vulnerable to unauthorized access, credential sharing, and uncontrolled digital content distribution. This study proposes an Authentication-Based Access Control Framework for secure web-based ebook distribution by integrating authentication, role-based authorization, session management, transaction validation, and ebook access protection within a unified security architecture.The research employed the Waterfall software development model consisting of requirement analysis, system design, implementation, testing, and deployment. The proposed framework was implemented using PHP and MySQL and evaluated through functional and security testing.The implementation results demonstrate that the developed system successfully manages 153 registered users, 151 ebook transactions, and six published ebook collections while maintaining controlled access to digital content. Functional testing achieved a 100% success rate across authentication, authorization, session validation, and ebook protection scenarios. The session management mechanism effectively prevented concurrent account usage and unauthorized access attempts.The novelty of this study lies in the integration of authentication, authorization, session validation, and ebook access protection within a dedicated framework specifically designed for ebook distribution. The proposed framework provides a practical, scalable, and cost-effective alternative for educational institutions and digital content providers seeking secure digital resource distribution without relying on complex Digital Rights Management (DRM) infrastructures.

Lingga Kurnia Ramadhani, Bajeng Nurul Widyaningrum, Wahyu Wijaya Widiyanto · 0 citations
Open access Jul 2026

Zero-Trust Multi-Factor Authentication for Secure Digital Payments: Design and Implementation

Digital payment security requires robust access protection against unauthorized login attempts, credential misuse, and device-based threats. This study designs and implements a Zero Trust architecture-based Multi-Factor Authentication (MFA) prototype to strengthen access control in digital payment applications. The proposed system integrates password-based authentication, Time-Based One-Time Password (TOTP), device-trust evaluation, adaptive step-up authentication, rate limiting, and audit logging in a single authentication workflow. The novelty lies in integrating Zero Trust principles with MFA and device-based contextual verification, so access decisions consider both user credentials and device trust. The prototype was implemented using a client-server architecture with Flask as the backend and PostgreSQL as the database. Evaluation was conducted using 50 automated test cases across five authentication scenarios: valid registered-device login, invalid password, invalid OTP, new-device login, and expired OTP. The results show that the proposed system achieved 100% detection accuracy, 0% Attack Success Rate (ASR), 0% False Acceptance Rate (FAR), 0% False Rejection Rate (FRR), 100% Authentication Success Rate, and 100% Step-Up Trigger Rate. Performance testing showed an average authentication latency of 197.45 ms with a standard deviation of 5.18 ms, indicating stable and responsive authentication performance. A preliminary usability assessment also indicated that the login, TOTP verification, and step-up authentication workflow remained understandable without unnecessary authentication friction. Overall, the proposed prototype provides a practical baseline for strengthening digital payment access security through Zero Trust-based MFA and context-aware authentication.

F. Carasiola, Rakhmadi Irfansyah Putra · 0 citations
Open access Jul 2026

Blockchain-enabled multi-layer multi-factor authentication framework for secure financial service access

Cybersecurity in financial services remains a significant challenge, as remote-access platforms are frequent targets of credential theft, phishing, session hijacking, replay attacks, and other authentication-related threats. This paper presents a multi-factor, multi-layer authentication framework designed to enhance the security and auditability of financial-service access. The proposed framework integrates biometric verification, one-time password (OTP) validation, adaptive risk-based authentication, challenge–response verification, ECC-based digital signatures, and a ledger-supported audit layer within a unified authentication architecture. The framework operates across four security layers: biometric identity verification, OTP validation, dynamic contextual risk assessment, and adaptive challenge–response authentication. To strengthen integrity, confidentiality, and non-repudiation, authentication records are hashed, digitally signed using client-side ECC private keys, encrypted using the server’s public key, and recorded within a cryptographically linked audit ledger. Unlike purely conceptual approaches, the proposed framework has been fully implemented using Python (Flask), SQLite, and Docker, demonstrating practical deployability in real-world environments. Experimental evaluation includes functional validation, adversarial security testing, and operational performance assessment. The results demonstrate strong resistance against multiple authentication-related attack scenarios, including brute-force, replay, session hijacking, phishing, and man-in-the-middle attacks, while maintaining acceptable operational performance. The findings indicate that the proposed framework improves authentication assurance, traceability, and security resilience for modern financial-service environments through the coordinated integration of biometric, cryptographic, behavioral, and ledger-based security controls.

H. Hamidi, Far. Fathi, S. Mohammadi · 1 citation
Open access Jul 2026

Transition to Password-Free and Phishing-Resistant Authentication in Enterprise Information Systems: A FIDO2/Passkey-Based Standards-Based Qualitative Assessment and Phased Implementation Framework

Password-based authentication is one of the most fundamental vulnerabilities of enterprise information systems. This vulnerability is exploited through phishing, credential stuffing, password reuse and real-time transmission attacks where an attacker intercepts data. With strong multi-factor authentication, the risk is minimized but human-mediated factors like SMS, time-based OTP, confirmation notifications may get affected through fake login pages and reverse proxy. In general, the paper presents an evaluation of the security, usability, recovery, governance and interoperability aspects of FIDO2/WebAuthn and passkey which to be used for enterprise authentication. As per standards and current research, the study is qualitative risk comparison of password, password+OTP, push MFA, device-bound passkey and synchronized passkey approach; it establishes threat-control mapping; and proposes Enterprises five-phase migration. Consequently, as the proof demonstrates, this passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain. Nonetheless, reliance on synchronization provider, account recovery processes, legacy applications, multi-user-device usage, loss of devices, and enterprise attestation requirements generate new clusters of risks. The framework will consist of the following phases: inventory and user segmentation; pilot implementation for high-risk accounts; rollout to the managed workforce; and recovery and telemetry optimisation towards a managed de-risking against passwords. According to the research, the deployment of passkeys should not merely be regarded as a new technology for logging in. When used, a passkey can be thought of as a comprehensive enterprise security programme that jointly transforms the identity lifecycle, help desk, device management, access policies, and incident response.

Oğuzhan Kilim · 0 citations
Open access Aug 2026

A SECURE AND EFFICIENT BLOCKCHAIN-BASED ACADEMIC RECORD VERIFICATION SYSTEM FOR PREVENTING CREDENTIAL FRAUD USING HASH-BASED INTEGRITY MECHANISMS

Credential fraud in academic institutions has emerged as a serious global concern, undermining the integrity of educational qualifications and professional trust. Traditional paper-based and centralised digital verification systems are susceptible to forgery, data tampering, and administrative delays. This paper proposes a Secure and Efficient Blockchain-Based Academic Record Verification System (SEBARVS) that leverages a private blockchain architecture combined with SHA-256 hash-based integrity mechanisms to prevent credential fraud. Rather than storing complete academic records on the blockchain, the proposed system stores only the cryptographic hash of each record, ensuring both data privacy and tamper-proofing. Authorised institutions act as permissioned nodes within the network, enabling real-time, decentralised verification without relying on any single trusted authority. The workflow encompasses record generation, hash computation, on-chain storage, and a streamlined verification algorithm. Experimental evaluation demonstrates that the proposed system achieves verification within 2 to 5 seconds, eliminates single points of failure, and significantly reduces operational costs relative to traditional approaches. Comparative analysis against conventional systems and generic blockchain implementations confirms the superiority of the proposed approach in terms of security, efficiency, scalability, and privacy. The system offers a practical, deployment-ready framework for universities, certification bodies, and employers worldwide.

Ritika Bansal · 0 citations
Open access Jul 2026

SmartGaurd: Real-Time Behavioral Analysis System for Malicious File Activity Detection

A SmartGaurd: Real-Time Behavioral Analysis System for Malicious File Activity Detection is designed to protect confidential organizational data using a layered security architecture that improves data confidentiality while minimizing the risk of unauthorized data exposure.

Prachi Jadhav, Sai Jadhav, N. R. Devadiga et al. · 0 citations