A Hybrid Blockchain Architecture for Two-Factor Authentication in Single Sign-On Systems


Yangeç D., KOYUN A.

Concurrency and Computation: Practice and Experience, cilt.38, sa.15, 2026 (SCI-Expanded, Scopus)

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 38 Sayı: 15
  • Basım Tarihi: 2026
  • Doi Numarası: 10.1002/cpe.70897
  • Dergi Adı: Concurrency and Computation: Practice and Experience
  • Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus, Aerospace Database, Applied Science & Technology Source, Compendex, INSPEC, zbMATH, Technology Collection (ProQuest)
  • Anahtar Kelimeler: authentication, blockchain technology, hybrid identity architecture, Hyperledger fabric, single sign-on, TOTP, two-factor authentication
  • Süleyman Demirel Üniversitesi Adresli: Evet

Özet

Single Sign-On (SSO) systems make authentication easier to manage, but their second-factor records and audit logs are often stored in databases controlled by a single operator. This creates a trust problem when authentication evidence must remain verifiable across organizational or regulatory boundaries. This study evaluated whether a permissioned blockchain can strengthen the integrity and auditability of Time-based One-Time Password (TOTP) verification without replacing the conventional SSO model. A working prototype was assessed through a database-backed comparison, direct blockchain workload measurements, and repeated endpoint-level measurements of latency, confidence intervals, and resource use. In a local two-organization test network, direct Hyperledger Caliper gateway measurements reached 893.4 TPS under a 1000 TPS target, with 19,997 of 20,000 verification transactions succeeding. This value represents the direct Fabric transaction path, not the REST endpoint. Under the corresponding 1000 TPS endpoint workload, REST/Fabric achieved 219.23 ± 0.38 TPS, whereas REST/PostgreSQL achieved 924.79 ± 6.82 TPS. These findings show that Fabric introduces substantial endpoint overhead and is most appropriate when ledger-replicated, tamper-evident evidence and configurable consortium governance are more important than raw authentication throughput. The hybrid design retains the compatibility and account-management benefits of conventional SSO while distributing second-factor evidence across authorized consortium peers.