Threshold Cryptography for Leakage-Resilient Single Sign-On: A Comparative Security Analysis and Architecture Framework
Abstract
Single Sign-On (SSO) is now a common way to log in to cloud platforms, enterprise systems, mobile apps, and shared digital services, but traditional deployments remain vulnerable to credential leakage, phishing, token theft, replay attacks, and identity-provider compromise. Recent research has turned to threshold cryptography and leakage-resilient authentication, which spread trust across several authentication servers to address these issues. This work presents a security analysis of modern SSO authentication methods, focusing on threshold-based and password-driven systems. A structured review of studies published between 2015 and 2026 was carried out using IEEE Xplore, Scopus, and PubMed. In total, 23 peer-reviewed studies were analyzed using three metrics: Security Coverage Score (SCS), Overhead Index (OI), and Utility Score (U). The analysis shows a clear shift from centralized authentication toward distributed, threshold-based SSO, which provides better protection against credential leaks and server breaches while remaining practical to implement. Based on this comparative analysis, the paper proposes a deployment-focused threshold SSO architecture and outlines future directions, including post-quantum security, adaptive authentication, and standardized benchmarking frameworks.