Institutional attendance underpins academic eligibility and statutory reporting, yet it remains easy to falsify. Manual roll-call, static QR codes and simple check-in apps are all defeated by proxy (“buddy”) attendance, and increasingly by remote relay, in which an absent student is marked present over a video call. This paper presents SmartAICampus, a multi-tenant campus operations platform whose core contribution is an anti-proxy attendance mechanism that composes three independent locks: a rotating time-based one-time password (TOTP) QR code, short-range Bluetooth Low Energy (BLE) proximity between the student and the teacher’s device, and a device-lock that binds each student to a single enrolled phone. The system follows a thin-client, fat-backend design on Firebase, with sensitive logic in Cloud Functions, role-based access enforced through custom claims, and per-institute data isolation. The work is assessed through Design Science Research: a matrix of 22 functional test cases, a catalogue of 12 proxy-attack simulations, and a micro-benchmark of the cryptographic scan path. Eleven of twelve attacks are blocked, the verification path costs under 0.1 ms per scan, and an automated suite of 146 tests passes. The findings support the claim that layering cheap, independent signals defeats proxy attendance that any single signal permits — while honestly bounding one residual attack and projecting, rather than load-testing, scale to institute size.
Introduction
This paper presents SmartAICampus, a secure, AI-era attendance system designed to reduce proxy and remote-relay attendance in Indian higher education. The study argues that conventional methods such as manual attendance, static QR codes, RFID, GPS, and single-factor biometric systems rely on signals that can be copied, shared, spoofed, or transferred to another person.
The proposed system uses three independent verification layers simultaneously:
Rotating TOTP-based QR code – changes every few seconds, making screenshots and replayed codes ineffective.
Bluetooth Low Energy (BLE) proximity – confirms that the student's phone is physically near the teacher's device.
Device-lock – binds each student account to one registered handset.
All critical verification is performed on the Firebase backend, with separate institutional data and role-based access controls.
Literature and Research Gap
Previous attendance systems generally depend on a single identifying factor:
Biometrics identify the person but raise privacy, cost, and scalability concerns.
RFID/NFC cards are convenient but can be handed to another student.
Static or dynamic QR codes improve convenience but can still be relayed remotely.
GPS/geofencing can be spoofed and is less reliable indoors.
BLE provides better physical-proximity verification but is insufficient alone.
The key research gap identified is the lack of a system that combines multiple independent signals at the exact moment of attendance, specifically addressing remote-relay attacks.
Methodology
The research follows a Design Science Research approach. A Flutter application was developed with Firebase services including Cloud Functions, Firestore, Authentication, Cloud Messaging, and App Check.
The system was evaluated using:
22 functional test cases
12 simulated proxy/remote-relay attacks
146 automated regression tests
Cryptographic performance benchmarking
Analysis of software defects and maintainability
Major Results
The system demonstrated strong performance:
Measure
Result
Functional tests
22/22 passed
Automated regression tests
146/146 passed
Proxy/relay attacks
11 of 12 blocked
Verification latency
< 0.1 ms/scan
Static analysis
No issues
Logged defects
9, with 6 resolved through backend deployment
The only attack not prevented was physical handover of the enrolled, unlocked phone. In this case, another person can use the legitimate device, and software-based signals cannot reliably distinguish this from genuine attendance.
Hypotheses
H1: Supported with one limitation. Three-factor verification successfully blocked 11/12 simulated attacks.
H2: Supported at the mechanism level. Verification requires less than 0.1 ms, although real classroom end-to-end timing was not measured.
H3: Partially supported. Institutional data isolation was demonstrated, but scalability to approximately 10,000 students was projected rather than experimentally load-tested.
Conclusion
SmartAICampus shows that composing cheap, independent signals — a rotating QR code, BLE proximity and a device-lock — defeats the proxy and remote-relay attendance that any single signal permits, within a maintainable, multi-tenant Firebase architecture that keeps each institution’s data isolated. Evaluated as Design Science Research on the built system, the mechanism blocks eleven of twelve simulated attacks at under 0.1 ms of verification cost per scan, while honestly bounding the one residual attack and projecting — rather than load-testing — scale to institute size. Beyond the artefact, the study contributes a reusable evaluation frame — a functional test matrix, an attack catalogue and a small set of performance metrics — that other anti-proxy attendance systems can adopt.
References
[1] O. T. Arulogun, A. Olatunbosun, O. A. Fakolujo, and O. M. Olaniyi, “RFID-based students attendance management system,” International Journal of Scientific & Engineering Research, vol. 4, no. 2, 2013.
[2] Z. Ayop, Y. L. Chan, S. Anawar, E. Hamid, and M. S. Azhar, “Location-aware event attendance system using QR code and GPS technology,” International Journal of Advanced Computer Science and Applications, vol. 9, no. 9, 2018.
[3] M. A. Ayu and B. I. Ahmad, “TouchIn: An NFC supported attendance system in a university environment,” International Journal of Information and Education Technology, vol. 4, no. 5, pp. 448–453, 2014.
[4] C.-P. Bezemer and A. Zaidman, “Multi-tenant SaaS applications: Maintenance dream or nightmare?” in Proc. Joint ERCIM Workshop on Software Evolution (EVOL) and Int. Workshop on Principles of Software Evolution (IWPSE), 2010, pp. 88–92.
[5] K. L. Bhatti, L. Mughal, F. Y. Khuhawar, and S. A. Memon, “Smart attendance management system using face recognition,” EAI Endorsed Transactions on Creative Technologies, vol. 5, no. 17, art. 159713, 2018.
[6] Bluetooth SIG, “Bluetooth core specification, version 5.4,” Bluetooth Special Interest Group, 2023.
[7] J. R. Fernandez, H. Mamarungkas, S. Vinson, and K. Atuel, “Facial and geofencing-based attendance tracking system for deployed personnel,” Mindanao Journal of Science and Technology, vol. 23, no. 2, pp. 133–148, 2025.
[8] A. R. Hevner, S. T. March, J. Park, and S. Ram, “Design science in information systems research,” MIS Quarterly, vol. 28, no. 1, pp. 75–105, 2004.
[9] M. Imanullah and Y. Reswan, “Randomized QR-code scanning for a low-cost secured attendance system,” International Journal of Electrical and Computer Engineering, vol. 12, no. 4, pp. 3762–3769, 2022.
[10] J. D. Irawan, E. Adriantantri, and A. Farid, “RFID and IoT for attendance monitoring system,” MATEC Web of Conferences, vol. 164, art. 01020, 2018.
[11] R. Josphineleela and M. Ramakrishnan, “An efficient automatic attendance system using fingerprint reconstruction technique,” International Journal of Computer Science and Information Security, vol. 10, no. 3, 2012.
[12] S. M. Khan, M. T. Maliha, M. S. Haque, and A. Rahman, “WiFi received signal strength (RSS) based automated attendance system for educational institutions,” in Proc. 11th Int. Conf. on Networking, Systems, and Security (NSysS), 2024.
[13] P. Kriz, F. Maly, and T. Kozel, “Improving indoor localization using Bluetooth Low Energy beacons,” Mobile Information Systems, vol. 2016, art. 2083094, 2016.
[14] M. Labayen, R. Vea, J. Florez, N. Aginako, and B. Sierra, “Online student authentication and proctoring system based on multimodal biometrics technology,” IEEE Access, vol. 9, pp. 72398–72411, 2021.
[15] F. Masalha and N. Hirzallah, “A students attendance system using QR code,” International Journal of Advanced Computer Science and Applications, vol. 5, no. 3, pp. 75–79, 2014.
[16] D. M’Raihi, S. Machani, M. Pei, and J. Rydell, “TOTP: Time-based one-time password algorithm,” Internet Engineering Task Force, RFC 6238, 2011.
[17] V. D. Nguyen, H. Van Khoa, T. N. Kieu, and E.-N. Huh, “Internet of Things-based intelligent attendance system: Framework, practice implementation, and application,” Electronics, vol. 11, no. 19, art. 3151, 2022.
[18] A. Nwabuwe, B. Sanghera, T. Alade, and F. Olajide, “Fraud mitigation in attendance monitoring systems using dynamic QR code, geofencing and IMEI technologies,” International Journal of Advanced Computer Science and Applications, vol. 14, no. 4, 2023.
[19] J. Patel, S. Gandhi, V. Katheriya, P. Pataliya, and A. Majumdar, “Enhancing classroom attendance systems with face recognition through CCTV using deep learning,” Procedia Computer Science, vol. 258, pp. 3031–3041, 2025.
[20] K. Peffers, T. Tuunanen, M. A. Rothenberger, and S. Chatterjee, “A design science research methodology for information systems research,” Journal of Management Information Systems, vol. 24, no. 3, pp. 45–77, 2007.
[21] A. Puckdeevongs, N. K. Tripathi, A. Witayangkurn, and P. Saengudomlert, “Classroom attendance systems based on Bluetooth Low Energy indoor positioning technology for smart campus,” Information, vol. 11, no. 6, art. 329, 2020.
[22] H. D. Rjeib, N. S. Ali, A. Al Farawn, B. Al-Sadawi, and H. Alsharqi, “Attendance and information system using RFID and web-based application for academic sector,” International Journal of Advanced Computer Science and Applications, vol. 9, no. 1, pp. 266–274, 2018.
[23] B. Soewito and E. W. M. Simanjuntak, “Efficiency optimization of attendance system with GPS and biometric method using mobile devices,” CommIT (Communication and Information Technology) Journal, vol. 8, no. 1, pp. 5–9, 2014.
[24] S. W. Taju, Y. P. Mamahit, and J. A. Pongantung, “Implementing QR code and geolocation technologies for the student attendance system,” CogITo Smart Journal, vol. 10, no. 1, pp. 221–232, 2024.
[25] N. O. Tippenhauer, C. Pöpper, K. B. Rasmussen, and S. ?apkun, “On the requirements for successful GPS spoofing attacks,” in Proc. ACM Conf. on Computer and Communications Security (CCS), 2011, pp. 75–86.
[26] Y. Zhuang, J. Yang, Y. Li, L. Qi, and N. El-Sheimy, “Smartphone-based indoor localization with Bluetooth Low Energy beacons,” Sensors, vol. 16, no. 5, art. 596, 2016.