SSO Protocols: SAML vs. OAuth2 vs. OpenID Connect – Comparative Security Analysis
- Version
- Download 4
- File Size 432.35 KB
- Download
SSO Protocols: SAML vs. OAuth2 vs. OpenID Connect - Comparative Security Analysis
Surya Ravikumar
suryark@gmail.com
Abstract: Single Sign-On (SSO) protocols enable users to authenticate only once and access a multitude of services, simplifying authentication across various systems and apps. Protocols such as SAML, OAuth2, and OpenID Connect have become industry standards due to the increased focus on security and user ease. With an emphasis on their security features, weaknesses, and applicability for different use scenarios, this study compares and contrasts these three protocols. The purpose of this study is to identify the advantages and disadvantages of each SSO protocol so that companies may choose the best one by looking at their authentication processes, token handling, cryptographic safeguards, and practical applications.
Keywords: SSO, SAML, OAuth2, OpenID Connect, Authentication, Security, Identity Federation, Access Tokens