Implementation of FIDO2/Webauthn-Based Multi-Factor Authentication Module for E-Commerce Security on Prestashop
Downloads
This study presents the design, implementation, and empirical validation of a FIDO2/WebAuthn-based Multi-Factor Authentication (MFA) module for the PrestaShop e-commerce platform. As e-commerce transactions continue to grow, conventional password-based authentication remains a critical vulnerability exploited by phishing and credential theft attacks. The proposed module integrates passwordless authentication and second-factor verification using the W3C WebAuthn Level 2 standard, implemented as a non-invasive PrestaShop module utilizing the platform’s native hook system. The module supports hardware security keys, platform authenticators (Windows Hello, Touch ID, Android Biometrics), and cross-device passkeys. Functional testing validates complete registration, authentication, and credential management flows across Chrome, Firefox, and Safari browsers. WebAuthn API testing confirms compliance with cryptographic security properties including origin binding, challenge entropy (256-bit), replay prevention, and signature verification. Results demonstrate that FIDO2-based authentication can be seamlessly integrated into existing e-commerce platforms without core system modifications, providing phishing-resistant authentication while maintaining backward compatibility with conventional password-based login.
Aburbeian, A. M., & Fernández-Veiga, M. (2024). Secure Internet Financial Transactions: A Framework Integrating Multi-Factor Authentication and Machine Learning. AI, 5(1),
-194. https://doi.org/10.3390/ai5010010
Affia, A. A. O., Matulevičius, R., & Nolte, A. (2020). Security Risk Management in E-Commerce Systems: A Threat-Driven Approach. Baltic Journal of Modern Computing, 8(2), 213-240.
https://doi.org/10.22364/bjmc.2020.8.2.02
Barbosa, M., Boldyreva, A., Chen, S., & Warinschi, B. (2021). Provable Security Analysis of FIDO2. In Advances in Cryptology - CRYPTO 2021 (pp. 125-156). Springer. https://doi.org/10.1007/978-3-030-84252-9_5
CISA. (2022). Implementing Phishing-Resistant MFA. https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
FIDO Alliance. (2018). FIDO User Authentication Specifications. https://fidoalliance.org/specifications
Islam, S. (2024). Impact of Online Payment Systems on Customer Trust and Loyalty in E-Commerce. Available at SSRN 5064838.
https://dx.doi.org/10.2139/ssrn.5064838
Kishnani, U., & Das, S. (2024). Dual-Technique Privacy & Security Analysis for E-Commerce Websites. arXiv preprint arXiv:2410.14960. https://doi.org/10.48550/arXiv.2410.14960
Krishnapatnam, M. (2025). Next-Generation Identity Security in Healthcare: A Passkey-Based Approach. International Journal of Computing and Engineering, 7(3), 23-33.
https://doi.org/10.47941/ijce.2701
Kunke, J., Wiefling, S., Ullmann, M., & Iacono, L. L. (2021). Evaluation of Account Recovery Strategies with FIDO2-Based Passwordless Authentication. arXiv preprint arXiv:2105.12477. https://doi.org/10.48550/arXiv.2105.12477
Meyer, L. A., Romero, S., Bertoli, G., Burt, T., Weinert, A., & Ferres, J. L. (2023). How Effective is Multifactor Authentication at Deterring Cyberattacks?. arXiv preprint arXiv:2305.00945. https://doi.org/10.48550/arXiv.2305.00945
Microsoft Threat Intelligence. (2023). Detecting and Mitigating a Multi-Stage AiTM Phishing and BEC Campaign. Microsoft Security Blog.
NIST. (2025). NIST SP 800-63 Digital Identity Guidelines. https://pages.nist.gov/800-63-4
Ou, H. H., Pan, C. H., Tseng, Y. M., & Lin, I. C. (2024). Decentralized Identity Authentication Mechanism: Integrating FIDO and Blockchain for Enhanced Security. Applied Sciences, 14(9), 3551. https://doi.org/10.3390/app14093551
OWASP. (2025). Introduction - OWASP Top 10:2025 RC1.
https://owasp.org/Top10/2025/0x00_2025-Introduction
PCMI. (2024). Indonesia’s E-commerce Market: Trends & Growth 2024-2027.
https://paymentscmi.com/insights/indonesia-ecommerce-market-data
PrestaShop. (2025). Developer Documentation. https://devdocs.prestashop-project.org
Rivera-Dourado, M., Gestal, M., Pazos, A., & Vázquez-Naya, J. M. (2021). An Analysis of the Current Implementations Based on the WebAuthn and FIDO Authentication Standards. Engineering Proceedings, 7(1), 56.
https://doi.org/10.3390/engproc2021007056
Rivera-Dourado, M., Gestal, M., Pazos, A., & Vázquez-Naya, J. (2024). A Novel Protocol Using Captive Portals for FIDO2 Network Authentication. Applied Sciences, 14(9), 3610.
https://doi.org/10.3390/app14093610
Rivera-Dourado, M., Xenakis, C., Pazos, A., & Vázquez-Naya, J. (2025). EAP-FIDO: A Novel EAP Method for Using FIDO2 Credentials for Network Authentication. Computer Networks, 111348. https://doi.org/10.1016/j.comnet.2025.111348
Spomky. (2025). web-auth/webauthn-framework: FIDO-U2F / FIDO2 / WebAuthn Framework. GitHub. https://github.com/web-auth/webauthn-framework
Store Leads. (2026). The State of PrestaShop in 2026. https://storeleads.app/reports/prestashop
W3C. (2021). Web Authentication: An API for Accessing Public Key Credentials - Level 2.
https://www.w3.org/TR/webauthn-2
Yadav, T. K., & Seamons, K. (2024). A Security and Usability Analysis of Local Attacks Against FIDO2. Network and Distributed System Security (NDSS) Symposium, 2024(327).
