Sack Key: An Offline Mobile Password Manager Application

Authors

  • Muhammad Afiq Haikal Ahmad Tarmizi Department of Computer Science, International Islamic University Malaysia, Kuala Lumpur, Malaysia
  • Muhammad Anwar Mohd Asri Department of Computer Science, International Islamic University Malaysia, Kuala Lumpur, Malaysia
  • Norlia Md Yusof Department of Computer Science, International Islamic University Malaysia, Kuala Lumpur, Malaysia

DOI:

https://doi.org/10.31436/ijpcc.v12i2.710

Keywords:

Password Manager, Offline-First, AES Encryption, Two-Factor Authentication, Mobile Security, Privacy.

Abstract

The rapid growth of online services has significantly increased the number of credentials users must manage, leading to widespread password reuse and weak authentication practices. This issue is particularly severe on mobile devices, where usability constraints often conflict with secure password management. Existing password managers commonly rely on cloud-based storage and subscription models, which introduce privacy concerns and increase exposure to centralized attacks. This paper presents Sack Key, a privacy-centric mobile password manager designed with an offline-first architecture to enhance security and user control. Sack Key securely stores credentials locally using AES-256 encryption and eliminates dependency on cloud infrastructure. The system incorporates multi-layer security mechanisms, including master password, Two-Factor Authentication (2FA), automatic session locking and privacy-preserving features such as manual encryption and decryption. Additionally, Sack Key supports secure peer-to-peer password sharing over local networks without internet connectivity. The results of functional, security and user testing indicate that Sack Key provides reliable password protection, strong user trust in offline security and intuitive user experience. The findings demonstrate that an offline-first password manager can effectively balance usability, security and privacy in mobile environments.

References

Verizon, 2025 Data Breach Investigations Report, Verizon Enterprise, 2025.

P. A. Cabarcos, M. G. López and J. L. Vázquez, “The more accounts I use, the less I have to think: A longitudinal study on the usability of password managers for novice users,” in Proc. USENIX Symp. Usable Privacy Secur. (SOUPS), 2025.

A. Ponticello, R. Kuber and S. Branham, “How blind and low-vision users manage their passwords,” in Proc. ACM Conf. Comput. Commun. Secur. (CCS), Nov. 2025, doi: 10.1145/3719027.3765081, 2025.

G. W. W. Mukti and R. Roestam, “Enhancing password manager application security by root detection with usability and security evaluation,” in Proc. 8th Int. Conf. Informatics Comput. (ICIC), pp. 1–7, doi: 10.1109/ICIC60109.2023.10382115, Dec. 01, 2023.

Y. Fu and D. Wang, “Leaky autofill: An empirical study on the privacy threat of password managers’ autofill functionality,” in Proc. Annu. Comput. Secur. Appl. Conf. (ACSAC), pp. 288–303, doi: 10.1109/ACSAC63791.2024.00037, Nov. 2024.

E. Chatzoglou, V. Kampourakis, Z. Tsiatsikas, G. Karopoulos and G. Kambourakis, “Keep your memory dump shut: Unveiling data leaks in password managers,” in IFIP Adv. Inf. Commun. Technol., vol. 710. Cham, Switzerland: Springer, pp. 63–78, doi: 10.1007/978-3-031-65175-5_5, 2024.

S. H. Pothineni, “Offline-first mobile architecture: enhancing usability and resilience in mobile systems,” Journal of Artificial Intelligence General Science (JAIGS), vol. 7, issue 1, Dec. 2024. [Online]. Available: https://www.researchgate.net/publication/393910615_Offline-First_Mobile_Architecture_Enhancing_Usability_and_Resilience_in_Mobile_Systems

D. Beh, N. Kaur, S. Verma and A. Joshi, “Cryptographic encryption techniques in a password manager,” in IET Conf. Proc., vol. 2023, no. 11, pp. 346–353, doi: 10.1049/icp.2023.1803, Jan. 2023.

H. Alsharaya, “Password managers: A critical review of security, usability and innovative designs,” J. Comput. Sci. Inst., vol. 36, pp. 328-335, June 2025.

A. T. Mahdad and N. Saxena, “Mobile login bridge: Subverting 2FA and passwordless authentication via Android Debug Bridge,” in Proc. 21st Int. Conf. Privacy, Security Trust (PST), pp. 1–12, doi: 10.1109/PST62714.2024.10788081, Aug. 2024.

E. Chatzoglou, V. Kampourakis, Z. Tsiatsikas, G. Karopoulos and G. Kambourakis, “Unmasking the hidden credential leaks in password managers,” Comput. Secur., vol. 140, Art. no. 103620, doi: 10.1016/j.cose.2024.103620, 2025.

C. Anliker, M. Staub and D. Basin, “Phishing attacks against password manager browser extensions,” in Proc. USENIX Secur. Symp., 2025.

M. Jubur, A. Alsaadi and K. Almarhabi, “An in-depth analysis of password managers and two-factor authentication (2FA) schemes,” ACM Comput. Surv., early access, doi: 10.1145/3711117, Jan. 2025.

M. Abdulkadir, S. Alketbi, H. Lamaazi, R. Altamimi, S. Alblooshi and A. Lakas, “Vault-PMS: A vault-based password management system for secure offline data storage,” in Proc. 20th Int. Wireless Commun. Mobile Comput. Conf. (IWCMC), pp. 1510–1515, doi: 10.1109/IWCMC61514.2024.10592442, May 2024.

A. Gangwal, S. Singh and A. Srivastava, “AutoSpill: Credential Leakage from Mobile Password Managers,” Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy, pp. 39–47, doi: https://doi.org/10.1145/3577923.3583658. Apr. 2023.

S. Tilley, System Analysis and Design, 12th ed., Boston, USA: Cengage, 2020.

Downloads

Published

31-07-2026

How to Cite

Ahmad Tarmizi, M. A. H. ., Mohd Asri, M. A., & Md Yusof, N. (2026). Sack Key: An Offline Mobile Password Manager Application. International Journal on Perceptive and Cognitive Computing, 12(2), 142–150. https://doi.org/10.31436/ijpcc.v12i2.710

Issue

Section

Articles