Abdilah, Dadan
(2025)
PENGAMANAN APPLICATION PROGRAMMING INTERFACE DENGAN PENERAPAN TWO-FACTOR AUTHENTICATION MENGGUNAKAN ALGORITMA TIME-BASED ONE TIME PASSWORD.
S1 / D3 thesis, Universitas Kuningan.
Abstract
Perkembangan teknologi informasi mendorong kebutuhan akan keamanan data, terutama dalam pertukaran informasi melalui Application Programming Interface (API). Salah satu metode pengamanan API adalah dengan menggunakan autentikasi berlapis. Penelitian ini mengimplementasikan Two-Factor Authentication (2FA) menggunakan algoritma Time-Based One Time Password (TOTP) untuk meningkatkan keamanan autentikasi API. Studi kasus dilakukan pada PT Kiosweb Teknologi Indonesia, dimana terdapat masalah autentikasi hanya menggunakan username dan password serta kerentanan pada API order akibat duplikat request. Metode pengembangan sistem yang digunakan adalah Extreme Programming (XP), sedangkan pengujian dilakukan dengan Postman, Burp Suite, serta pengujian black-box dan white-box. Hasil penelitian menunjukkan bahwa penerapan 2FA berbasis TOTP dapat meningkatkan keamanan login dan transaksi, mencegah duplikat request, serta memverifikasi keabsahan permintaan API menggunakan JSON Web Token (JWT). Implementasi ini berhasil mengurangi potensi serangan dan meningkatkan keamanan sistem transaksi berbasis web.
Kata Kunci : API, Two-Factor Authentication, Time-Based One-Time Password, Keamanan Data.
The advancement of information technology has increased the demand for robust data security, particularly in the exchange of information via Application Programming Interfaces (APIs). One effective approach to securing APIs is the use of layered authentication. This study implements Two-Factor Authentication (2FA) using the Time-Based One-Time Password (TOTP) algorithm to enhance API security. A case study was conducted at PT Kiosweb Teknologi Indonesia, where authentication issues were identified due to the use of only username and password, as well as vulnerabilities in the order API caused by duplicate requests. The system was developed using the Extreme Programming (XP) methodology, and testing was performed using Postman, Burp Suite, and both black-box and white-box testing methods. The results show that the TOTP-based 2FA implementation effectively improves login and transaction security, prevents duplicate requests, and verifies the validity of API requests using JSON Web Token (JWT). This implementation successfully mitigates potential attacks and strengthens the security of web-based transaction systems.
Keywords : API, Two-Factor Authentication, Time-Based One Time Password, System Security.
Actions (login required)

- View Item