Beyond Random Suffixes: Security Analysis and a Cryptographically Hardened Reference-Number Protocol for Web-Based Academic Credential Verification, with a Case Implementation at Northwest University, Kano

Abstract: Many institution-level credential-verification systems generate a random-looking reference code and treat it as secure by virtue of being unique, without examining whether that code is actually resistant to guessing. This paper re-examines a deployed reference-number scheme built for the Academic Document Verification System at Northwest University (NWU), Kano, and shows that its uniqueness suffix - four hexadecimal characters drawn from a UUID4 - carries only 16 bits of entropy (65,536 possible values). We show analytically and by Monte Carlo simulation that, while the system's retry-on-collision loop guarantees no reference is ever issued twice, the same 16-bit space can be exhaustively enumerated against the public verification endpoint in under 11 minutes at a modest 100 requests per second, since no rate limiting is applied. We then design, specify, and analyse a drop-in replacement: an HMAC-SHA256-derived tag computed over the year, document-type, department, and a monotonic serial number, keyed by a server-side secret. At a 48-bit truncation this raises brute-force exhaustion time to an estimated 89,000 years under the same attack rate, at a measured computational cost of 3.2 microseconds per generation or verification - statistically negligible against the system's sub-second query latency. The two schemes are compared against manual, QR-code-based, blockchain-anchored, and zero-knowledge credential-verification approaches reported in the literature on a five-dimension feature matrix, supplemented by a quantitative verification-time comparison. The system was validated through 34 functional test cases (100% pass rate) and an exploratory, formative user-acceptance evaluation (n=8; overall satisfaction 4.5-4.8/5.0, not powered for statistical inference), in which security confidence was the lowest-rated criterion - a finding consistent with, though not statistically proof of, the entropy weakness this paper identifies and addresses. The contribution of this paper is therefore not the verification system as an artefact, but a transferable method for quantifying and closing the guessability gap in identifier-based credential-verification schemes generally.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-12
DOI
https://doi.org/10.5281/zenodo.22726377
Primary Topic
QR Code Applications and Technologies
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Beyond Random Suffixes: Security Analysis and a Cryptographically Hardened Reference-Number Protocol for Web-Based Academic Credential Verification, with a Case Implementation at Northwest University, Kano

Usman Mahmud, Fatima Shehu Tofa, Abdullahi Abdulwahab, Yusuf Aliyu Adamu* et al.
Zenodo (CERN European Organization for Nuclear Research)
QR Code Applications and Technologies
article

Beyond Random Suffixes: Security Analysis and a Cryptographically Hardened Reference-Number Protocol for Web-Based Academic Credential Verification, with a Case Implementation at Northwest University, Kano

Usman Mahmud, Fatima Shehu Tofa, Abdullahi Abdulwahab, Yusuf Aliyu Adamu*, Sani Bature Sufyan, Faruk Aliyu Fari
article en

Abstract

Abstract: Many institution-level credential-verification systems generate a random-looking reference code and treat it as secure by virtue of being unique, without examining whether that code is actually resistant to guessing. This paper re-examines a deployed reference-number scheme built for the Academic Document Verification System at Northwest University (NWU), Kano, and shows that its uniqueness suffix - four hexadecimal characters drawn from a UUID4 - carries only 16 bits of entropy (65,536 possible values). We show analytically and by Monte Carlo simulation that, while the system's retry-on-collision loop guarantees no reference is ever issued twice, the same 16-bit space can be exhaustively enumerated against the public verification endpoint in under 11 minutes at a modest 100 requests per second, since no rate limiting is applied. We then design, specify, and analyse a drop-in replacement: an HMAC-SHA256-derived tag computed over the year, document-type, department, and a monotonic serial number, keyed by a server-side secret. At a 48-bit truncation this raises brute-force exhaustion time to an estimated 89,000 years under the same attack rate, at a measured computational cost of 3.2 microseconds per generation or verification - statistically negligible against the system's sub-second query latency. The two schemes are compared against manual, QR-code-based, blockchain-anchored, and zero-knowledge credential-verification approaches reported in the literature on a five-dimension feature matrix, supplemented by a quantitative verification-time comparison. The system was validated through 34 functional test cases (100% pass rate) and an exploratory, formative user-acceptance evaluation (n=8; overall satisfaction 4.5-4.8/5.0, not powered for statistical inference), in which security confidence was the lowest-rated criterion - a finding consistent with, though not statistically proof of, the entropy weakness this paper identifies and addresses. The contribution of this paper is therefore not the verification system as an artefact, but a transferable method for quantifying and closing the guessability gap in identifier-based credential-verification schemes generally.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 3%
QR Code Applications and Technologies
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.