MULTI-FACTOR AUTHENTICATION IN IMPROVING THE SECURITY OF IOT DEVICES AGAINST CYBER-ATTACKS: A SYSTEMATIC LITERATURE REVIEW
Main Article Content
Abstract
Security aspects in the development and deployment of IoT devices are often crucial but overlooked. This is evident from the number of IoT devices that are faced with cyber threats due to suboptimal security systems. The reason for this problem is because during the development stage of IoT devices, some developers do not pay special attention to the implementation of strong security protocols. Based on these problems, this literature review aims to examine the extent to which Multi-Factor Authentication (MFA) can improve the security of IoT devices, especially in the face of increasingly complex cyber attacks. This literature review uses the Systematic Literature Review (SLR) method with the PRISMA framework approach to ensure a systematic and analytical review of related literature. Of the 155 journals traced with a time span of 2010 - 2024, 21 journals were obtained that met the predetermined eligibility criteria. Based on the results of the literature review, the implementation of Multi-Factor Authentication (MFA) on Internet of Things (IoT) devices is considered capable of mitigating and handling several security attack threats such as brute force attacks, Man-in-the-Middle (MITM), insider attacks, replay attacks, and other attacks.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with Positif : Jurnal Sistem dan Teknologi Informasi agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.

This work is licensed under a Creative Commons Attribution 4.0 International License.
References
M. Wu and X. Chen, “Application of Internet of Things and embedded technology in electronic communication,” Meas. Sens., vol. 34, p. 101246, Aug. 2024, doi: 10.1016/j.measen.2024.101246.
C. Fernandez-Gago, D. Ferraris, R. Roman, and J. Lopez, “Trust interoperability in the Internet of Things,” Internet Things, vol. 26, p. 101226, Jul. 2024, doi: 10.1016/j.iot.2024.101226.
Z. Xie, W. Bu, H. Feng, and Y. Wang, “Integrated development of the industrial chain and innovation chain of high-tech manufacturing industry based on the Internet of Things,” Alex. Eng. J., vol. 108, pp. 828–838, Dec. 2024, doi: 10.1016/j.aej.2024.09.052.
S. F. Ahmed, Md. S. B. Alam, S. Afrin, S. J. Rafa, N. Rafa, and A. H. Gandomi, “Insights into Internet of Medical Things (IoMT): Data fusion, security issues and potential solutions,” Inf. Fusion, vol. 102, p. 102060, Feb. 2024, doi: 10.1016/j.inffus.2023.102060.
V. Padmavathi and R. Saminathan, “Chapter 19 - Security for the Internet of Things,” in Computer and Information Security Handbook (Fourth Edition), J. R. Vacca, Ed., Morgan Kaufmann, 2025, pp. 353–368. doi: 10.1016/B978-0-443-13223-0.00019-9.
Zaed Mahdi, Nada Abdalhussien, Naba Mahmood, and Rana Zaki, “Detection of Real-Time Distributed Denial-of-Service (DDoS) Attacks on Internet of Things (IoT) Networks Using Machine Learning Algorithms,” Comput. Mater. Contin., vol. 80, no. 2, pp. 2139–2159, Aug. 2024, doi: 10.32604/cmc.2024.053542.
Dr. S. Choudhary and G. Meena, “Internet of Things: Protocols, Applications and Security Issues,” Procedia Comput. Sci., vol. 215, pp. 274–288, Jan. 2022, doi: 10.1016/j.procs.2022.12.030.
M. Kokila and S. Reddy K, “Authentication, access control and scalability models in Internet of Things Security–A review,” Cyber Secur. Appl., vol. 3, p. 100057, Dec. 2025, doi: 10.1016/j.csa.2024.100057.
“Internet of Things Authentication Protocols: Comparative Study,” Comput. Mater. Contin., vol. 79, no. 1, pp. 65–91, Apr. 2024, doi: 10.32604/cmc.2024.047625.
R. Kanmani, “Secure communication using light-weight cryptography and 2-factor verification for Iot devices,” Pak. J. Biotechnol., vol. 14, no. 3, pp. 459–462, 2017.
K. Y. Lam, “Identity in the internet-of-things (IoT): New challenges and opportunities,” Lect. Notes Comput. Sci. Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinforma., vol. 9977, no. Query date: 2024-09-24 19:15:48, pp. 18–26, 2016, doi: 10.1007/978-3-319-50011-9_2.
S. Rajashree, “Security Model for Internet of Things End Devices,” Proc. - IEEE 2018 Int. Congr. Cybermatics 2018 IEEE Conf. Internet Things Green Comput. Commun. Cyber Phys. Soc. Comput. Smart Data Blockchain Comput. Inf. Technol. IThingsGreenComCPSComSmartDataBlockchainCIT 2018, no. Query date: 2024-09-24 19:15:48, pp. 219–221, 2018, doi: 10.1109/Cybermatics_2018.2018.00066.
M. K. Rao, “Multi factor user authentication mechanism using internet of things,” ACM Int. Conf. Proceeding Ser., no. Query date: 2024-09-24 19:16:25, 2019, doi: 10.1145/3339311.3339335.
P. Jain, “MAFIA: Multi-layered Architecture for IoT-based Authentication,” Proc. - 2020 2nd IEEE Int. Conf. Trust Priv. Secur. Intell. Syst. Appl. TPS-ISA 2020, no. Query date: 2024-09-24 19:16:25, pp. 199–208, 2020, doi: 10.1109/TPS-ISA50397.2020.00035.
M. Safkhani, “RESEAP: An ECC-Based Authentication and Key Agreement Scheme for IoT Applications,” IEEE Access, vol. 8, no. Query date: 2024-09-24 19:16:25, pp. 200851–200862, 2020, doi: 10.1109/ACCESS.2020.3034447.
R. F. Al-Mutawa, “A smart home system based on internet of things,” Int. J. Adv. Comput. Sci. Appl., no. 2, pp. 260–267, 2020, doi: 10.14569/ijacsa.2020.0110234.
M. Gowtham, “Secure Internet-of- Things: Assessing Challenges and Scopes for NextGen Communication,” 2019 2nd Int. Conf. Intell. Comput. Instrum. Control Technol. ICICICT 2019, no. Query date: 2024-09-24 19:15:48, pp. 151–158, 2019, doi: 10.1109/ICICICT46008.2019.8993327.
A. J. Mohammed, “Efficient and flexible multi-factor authentication protocol based on fuzzy extractor of administrator’s fingerprint and smart mobile device,” Cryptography, vol. 3, no. 3, pp. 1–222, 2019, doi: 10.3390/cryptography3030024.
R. Shah, “A multifactor authentication system using secret splitting in the perspective of Cloud of Things,” 2017 Int. Conf. Emerg. Trends Innov. ICT ICEI 2017, no. Query date: 2024-09-24 19:16:25, pp. 1–4, 2017, doi: 10.1109/ETIICT.2017.7977000.
M. Najam-Ul-Islam, “Recursive Cryptanalysis of the IoT Authentication Protocol,” Proc. - 2019 IEEE 1st Glob. Power Energy Commun. Conf. GPECOM 2019, no. Query date: 2024-09-24 19:16:25, pp. 1–4, 2019, doi: 10.1109/GPECOM.2019.8778569.
P. Dhillon, “A secure multi-factor ECC based authentication scheme for Cloud-IoT based healthcare services,” J. Ambient Intell. Smart Environ., vol. 11, no. 2, pp. 149–164, 2019, doi: 10.3233/AIS-190516.
D. Shehada, “Performance Evaluation of a Lightweight IoT Authentication Protocol,” 2020 3rd Int. Conf. Signal Process. Inf. Secur. ICSPIS 2020, no. Query date: 2024-09-24 19:16:25, 2020, doi: 10.1109/ICSPIS51252.2020.9340146.
H. Rekha, “Model Checking M2M and Centralised IOT authentication Protocols,” J. Phys. Conf. Ser., vol. 2161, no. 1, 2022, doi: 10.1088/1742-6596/2161/1/012042.
M. Saideh, “Opportunistic Sensor-Based Authentication Factors in and for the Internet of Things,” Sensors, vol. 24, no. 14, 2024, doi: 10.3390/s24144621.
M. Mehta, “EFFICIENT FRAMEWORK OF SECURITY FOR INTERNET OF THINGS,” Reliab. Theory Appl., vol. 19, no. 1, pp. 217–227, 2024, doi: 10.24412/1932-2321-2024-177-217-227.
S. Atiewi, “Scalable and Secure Big Data IoT System Based on Multifactor Authentication and Lightweight Cryptography,” IEEE Access, vol. 8, no. Query date: 2024-09-24 19:16:25, pp. 113498–113511, 2020, doi: 10.1109/ACCESS.2020.3002815.
A. Haenel, “Practical cross-layer radio frequency-based authentication scheme for internet of things,” Sensors, vol. 21, no. 12, 2021, doi: 10.3390/s21124034.
K. Fan, “Lightweight NFC protocol for privacy protection in mobile IoT,” Appl. Sci. Switz., vol. 8, no. 12, 2018, doi: 10.3390/app8122506.
B. Chatterjee, “RF-PUF: Enhancing IoT Security Through Authentication of Wireless Nodes Using In-Situ Machine Learning,” IEEE Internet Things J., vol. 6, no. 1, pp. 388–398, 2019, doi: 10.1109/JIOT.2018.2849324.
P. Emami-Naeini, “Are Consumers Willing to Pay for Security and Privacy of IoT Devices?,” 32nd USENIX Secur. Symp. USENIX Secur. 2023, vol. 3, no. Query date: 2024-09-24 19:15:48, pp. 1505–1522, 2023.