Implementation of FIDO2/Webauthn-Based Multi-Factor Authentication Module for E-Commerce Security on Prestashop

FIDO2, WebAuthn, Multi-Factor Authentication, E-Commerce Security, PrestaShop, Passwordless Authentication

Authors

  • Muh. Zaki Erbai Syas Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
  • Rahmad Abdillah Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
  • Novriyanto Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
  • Suwanto Sanjaya Department of Informatics Engineering, Faculty of Science and Technology, Universitas Islam Negeri Sultan Syarif Kasim Riau, Indonesia
April 30, 2026
May 1, 2026

Downloads

This study presents the design, implementation, and empirical validation of a FIDO2/WebAuthn-based Multi-Factor Authentication (MFA) module for the PrestaShop e-commerce platform. As e-commerce transactions continue to grow, conventional password-based authentication remains a critical vulnerability exploited by phishing and credential theft attacks. The proposed module integrates passwordless authentication and second-factor verification using the W3C WebAuthn Level 2 standard, implemented as a non-invasive PrestaShop module utilizing the platform’s native hook system. The module supports hardware security keys, platform authenticators (Windows Hello, Touch ID, Android Biometrics), and cross-device passkeys. Functional testing validates complete registration, authentication, and credential management flows across Chrome, Firefox, and Safari browsers. WebAuthn API testing confirms compliance with cryptographic security properties including origin binding, challenge entropy (256-bit), replay prevention, and signature verification. Results demonstrate that FIDO2-based authentication can be seamlessly integrated into existing e-commerce platforms without core system modifications, providing phishing-resistant authentication while maintaining backward compatibility with conventional password-based login.