Implementation of Argon2i Algorithm in A Gamification-Based Habit Tracker Application for Account Security on Android Platform

Abstract Views: 10   PDF Downloads: 5

Authors

  • Isnainy Rodiah Universitas Islam Sumatera Utara
  • Khairuddin Nasution Universitas Islam Sumatera Utara
  • Rachmat Aulia Universitas Harapan Medan

DOI:

https://doi.org/10.56211/tsabit99

Keywords:

Argon2i; Password Hashing; Android Security; Habit Tracker; Gamification

Abstract

The rapid penetration of smartphones in Indonesia has driven the growth of the productivity application ecosystem, one of which is the gamification-based habit tracker application. However, this type of application indirectly collects users' sensitive daily routine data, while the majority of local applications still store passwords in plaintext form or use traditional hashing algorithms such as MD5 and SHA-256, which are vulnerable to GPU- and ASIC-based brute-force attacks. This research aims to design and implement the Argon2 algorithm (Argon2i variant) as an account security system for a gamification-based Android habit tracker application. The system was built using the Kotlin language, the Jetpack Compose framework, MVVM architecture, and Jetpack DataStore as local storage, with a layered security scheme (Dual-Layer Security) integrating Firebase Authentication as the first layer and an Argon2i-based App Lock as the second layer. The Argon2i algorithm was configured with a memory cost parameter of 64 MB (m=65536), a time cost of 2 iterations (t=2), and 1 parallel lane (p=1), producing a strong hash value resistant to specialized hardware exploitation. Functional testing using the Black Box Testing method across two iterations showed that all test scenarios (100%) passed after the debugging process, proving that the cryptographic system successfully secured user credentials without disrupting the application's stability and speed. This research produces a technical blueprint for integrating Argon2i password hashing into Android applications as a reference standard for account security on mobile devices.

Downloads

Download data is not yet available.

References

[1] S. Kemp, "Digital 2024: Indonesia," We Are Social & Meltwater, 2024. [Online]. Available: https://datareportal.com/reports/digital-2024-indonesia

[2] Putra et al., "Pengembangan Aplikasi Habit Tracker untuk Peningkatan Produktivitas Mahasiswa," Jurnal Sistem Informasi Akademik, 2022.

[3] A. Alrizal, "Pengembangan Aplikasi Habit Tracker Berbasis Android dengan Algoritma Weighted Scoring," Undergraduate Thesis, Universitas Islam Sumatera Utara, 2026.

[4] Yolandari et al., "Simulasi dan Perbandingan Hashing Password antara Algoritma Argon2 dan Scrypt," Jurnal Rekayasa Perangkat Lunak, 2026.

[5] J. Tippe and A. Berner, "Analisis Serangan Berbasis GPU dan ASIC terhadap Algoritma Hashing Tradisional," Jurnal Keamanan Sistem Informasi, 2025.

[6] BSSN, "Laporan Tahunan Keamanan Siber Indonesia 2024," Badan Siber dan Sandi Negara, 2024.

[7] Verizon, "Data Breach Investigations Report (DBIR) 2023," Verizon Enterprise, 2023. [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/

[8] Suendri, "Hashing Argon2 Untuk Keamanan Password Pada Sistem Berbasis Web Menggunakan PHP," JISTech (Journal of Islamic Science and Technology), vol. 4, no. 1, pp. 46–56, 2019.

[9] A. Biryukov, D. Dinu, and D. Khovratovich, "Argon2: New Generation of Memory-Hard Functions for Password Hashing and Other Applications," in Proc. IEEE European Symposium on Security and Privacy (EuroS&P), 2017, pp. 292–302.

[10] N. T. Jehian et al., "Keamanan Sistem Login Menggunakan Multifactor Authentication dan Algoritma Hashing," Journal of Information System, Informatics and Computing (JISICOM), vol. 9, no. 2, 2025.

[11] A. Muliawan and S. Hasnawati, "Penguatan Mekanisme Autentikasi Aplikasi Mobile sebagai Lini Pertahanan Data," Jurnal Teknologi Informasi, vol. 10, no. 2, 2024.

[12] R. S. Pressman and B. R. Maxim, Software Engineering: A Practitioner's Approach, 9th ed. New York: McGraw-Hill Education, 2020.

[13] Google Developers, "Android Developers Documentation: Kotlin and Jetpack Compose," 2023. [Online]. Available: https://developer.android.com

[14] D. Jemerov and S. Isakova, Kotlin in Action. Shelter Island, NY: Manning Publications, 2017.

[15] W. Kurniawan, I. Prihandi, and N. Husufa, "Prototype Firebase Authentication Menggunakan Fitur Firebase Pada Aplikasi Android," Jurnal Satya Informatika, vol. 4, no. 1, pp. 71–78, 2019.

[16] H. Y. P. Napitupulu and I. G. D. Nugraha, "Sistem Berbasis Komputasi Kabut Untuk Sistem Parkir Pintar Terdesentralisasi Menggunakan Firebase," Jurnal Nasional Teknik Elektro dan Teknologi Informasi (JNTETI), vol. 13, no. 1, 2024.

[17] C. Hanifurohman and D. D. Hutagalung, "Analisis Statis Menggunakan Mobile Security Framework untuk Pengujian Keamanan Aplikasi Mobile E-Commerce Berbasis Android," SEBATIK, vol. 25, no. 1, pp. 22–29, 2021.

[18] A. Caniago and T. Sutabri, "Analisis Dampak Psikologis dan Finansial Akibat Kebocoran Data Pribadi," Jurnal Keamanan Siber, vol. 5, no. 2, 2023.

[19] R. Octavia et al., "Analisis Kerentanan Autentikasi pada Aplikasi Mobile," Jurnal Keamanan Siber, 2024.

[20] Putra et al., "Dampak Finansial dari Pengambilalihan Akun Digital," Jurnal Keuangan dan Siber, 2024.

[21] R. Hutagaol et al., "Kesadaran Keamanan Siber pada Pengguna Smartphone di Indonesia," Jurnal Komputer dan Keamanan, vol. 11, no. 1, 2024.

[22] J. Wetzels, "Open Source Password Hashing: Argon2," Security Research Paper, 2015.

[23] Y. Amrozi et al., "Tantangan Security dan Kehandalan Sistem dalam Aplikasi Bergerak," Jurnal Pendidikan Teknologi Informasi (JUKANTI), vol. 4, no. 2, pp. 1–10, 2021.

[24] Dian et al., "Implementasi Jetpack Compose pada Antarmuka Pengguna Aplikasi Android," Jurnal Teknologi Mobile, vol. 8, no. 3, 2022.

Downloads

Published

2026-07-14

PlumX Metrics