Beyond Random Suffixes: Security Analysis and a Cryptographically Hardened Reference-Number Protocol for Web-Based Academic Credential Verification, with a Case Implementation at Northwest University, Kano
Abstract: Many institution-level credential-verification systems generate a random-looking reference code and treat it as secure by virtue of being unique, without examining whether that code is actually resistant to guessing. This paper re-examines a deployed reference-number scheme built for the Academic Document Verification System at Northwest University (NWU), Kano, and shows that its uniqueness suffix - four hexadecimal characters drawn from a UUID4 - carries only 16 bits of entropy (65,536 possible values). We show analytically and by Monte Carlo simulation that, while the system's retry-on-collision loop guarantees no reference is ever issued twice, the same 16-bit space can be exhaustively enumerated against the public verification endpoint in under 11 minutes at a modest 100 requests per second, since no rate limiting is applied. We then design, specify, and analyse a drop-in replacement: an HMAC-SHA256-derived tag computed over the year, document-type, department, and a monotonic serial number, keyed by a server-side secret. At a 48-bit truncation this raises brute-force exhaustion time to an estimated 89,000 years under the same attack rate, at a measured computational cost of 3.2 microseconds per generation or verification - statistically negligible against the system's sub-second query latency. The two schemes are compared against manual, QR-code-based, blockchain-anchored, and zero-knowledge credential-verification approaches reported in the literature on a five-dimension feature matrix, supplemented by a quantitative verification-time comparison. The system was validated through 34 functional test cases (100% pass rate) and an exploratory, formative user-acceptance evaluation (n=8; overall satisfaction 4.5-4.8/5.0, not powered for statistical inference), in which security confidence was the lowest-rated criterion - a finding consistent with, though not statistically proof of, the entropy weakness this paper identifies and addresses. The contribution of this paper is therefore not the verification system as an artefact, but a transferable method for quantifying and closing the guessability gap in identifier-based credential-verification schemes generally.
Authors
- Usman Mahmud (ORCID: https://orcid.org/0009-0006-2194-6585)
- Fatima Shehu Tofa (ORCID: https://orcid.org/0009-0000-6243-7679)
- Abdullahi Abdulwahab
- Yusuf Aliyu Adamu*
- Sani Bature Sufyan
- Faruk Aliyu Fari
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-12
- DOI
- https://doi.org/10.5281/zenodo.22726377
- Primary Topic
- QR Code Applications and Technologies
- Type
- article
- Field-Weighted Citation Impact
- 0.00