Design and Quantitative Evaluation of a Keycloak-Based Single Sign-On Architecture for Integrated Institutional Information Systems


Nurhadi Nurhadi(1*); Mustazzihim Suhaidi(2); Muhammad Athariq(3);

(1) Institut Teknologi dan Bisnis Riau Pesisir
(2) Institut Teknologi dan Bisnis Riau Pesisir
(3) Institut Teknologi dan Bisnis Riau Pesisir
(*) Corresponding Author

  

Abstract


The increasing integration of digital services in higher education institutions requires a secure and scalable authentication mechanism to ensure consistent access across multiple systems. However, fragmented authentication approaches often result in repeated login processes, inconsistent security policies, and inefficient identity management. This study proposes a modular Single Sign-On (SSO) architecture based on Keycloak, integrated with OAuth 2.0, OpenID Connect, and JSON Web Tokens (JWT), to support unified authentication in institutional information systems. A quantitative experimental approach is employed to evaluate system performance in a real academic environment involving 100 user accounts. The evaluation focuses on authentication efficiency, scalability, reliability, and user productivity. The results show a 62% reduction in average login time, an 85% increase in authentication throughput, and a 100% authentication success rate. Scalability testing indicates stable system performance under concurrent workloads, while token validation overhead remains minimal, ensuring that security enhancements do not degrade system responsiveness. In addition, task completion time decreases by 51%, accompanied by a significant improvement in user productivity. These findings demonstrate that the proposed Keycloak-based SSO architecture provides measurable improvements in performance, scalability, security governance, and usability. The study contributes to software systems engineering by presenting a validated architectural model and a comprehensive quantitative evaluation framework for identity management in higher education environments.


Keywords


Single Sign-On; Keycloak; Identity and Access Management; Oauth 2.0; OpenID Connect; Institutional Information Systems

  
  

Full Text:

PDF
  

Article Metrics

Abstract view: 90 times
PDF view: 15 times
     

Digital Object Identifier

doi  https://doi.org/10.33096/ilkom.v18i2.3368.237-254
  

Cite

References


A. Wairagade and S. Ranjan, “AI in Identity and Access Management (IAM) for Enterprise Systems: A Comparative Analysis,” Procedia Comput. Sci., vol. 263, pp. 167–174, 2025, doi: 10.1016/j.procs.2025.07.021.

A. Ramdhani and N. Legowo, “Modeling and Deploying RESTful Services with SOMF-Based SOA : A Case Study in the Credit Guarantee Industry,” J. RESTI (Rekayasa Sist. dan Teknol. Informasi), vol. 9, no. 5, pp. 1242–1254, 2024, doi: 10.29207/resti.v9i5.6867.

V. V. Sudrajat, R. D. Adityo, and A. Arizal, “Simulation of the Single Sign-On Method for Service Provider Applications: A Case Study of Bhayangkara University Surabaya,” JITE (Journal Informatics Telecommun. Eng., vol. 1, no. 9, pp. 36–47, 2025, doi: 10.31289/jite.v9i1.13750.

F. Buccafurri, V. De Angelis, and S. Lazzaro, “Enabling anonymized open-data linkage by authorized parties,” J. Inf. Secur. Appl., vol. 74, no. March, p. 103478, 2023, doi: 10.1016/j.jisa.2023.103478.

R. Article, V. K. Shanmughan, and I. Researcher, “Keycloak Implementation for Identity Management in SASE Architectures : A Regional Hub Approach,” Sarcouncil J. Multidiscip., vol. 0, pp. 1001–1007, 2025.

A. R. Pratama, F. M. Firmansyah, and F. Rahma, “Security awareness of single sign-on account in the academic community: the roles of demographics, privacy concerns, and Big-Five personality,” PeerJ Comput. Sci., vol. 8, pp. 1–20, 2022, doi: 10.7717/PEERJ-CS.918.

Y. Wang, P. Castillejo, J. F. Martínez-Ortega, and V. Hernández Díaz, “A survey on Identity and Access Management for future IoT services,” Comput. Networks, vol. 272, no. August, p. 111718, 2025, doi: 10.1016/j.comnet.2025.111718.

M. F. Digital and H. System, “A Cyber Risk Assessment Approach to Federated Identity,” Sensors, pp. 1–30, 2024.

Salmuasih and M. A. Setiawan, “Evaluasi Penerapan Single Sign-on Saml Dan Oauth 2.0: Studi Pada Perguruan Tinggi Yogyakarta,” JSiI (Jurnal Sist. Informasi), vol. 10, no. 1, pp. 41–49, 2023, doi: 10.30656/jsii.v10i1.6186.

D. Mortágua, A. Zúquete, and P. Salvador, “Enhancing 802.1X authentication with identity providers using EAP-OAUTH and OAuth 2.0,” Comput. Networks, vol. 244, no. June 2023, p. 110337, 2024, doi: 10.1016/j.comnet.2024.110337.

K. Chaturvedi, A. Matheus, S. H. Nguyen, and T. H. Kolbe, “Securing Spatial Data Infrastructures for Distributed Smart City applications and services,” Futur. Gener. Comput. Syst., vol. 101, pp. 723–736, 2019, doi: 10.1016/j.future.2019.07.002.

G. Zachmann, M. Hardt, and D. Gudu, “oidc-agent - Integrating OpenID Connect Tokens with the Command Line,” Comput. Softw. Big Sci., vol. 9, no. 1, pp. 1–9, 2025, doi: 10.1007/s41781-025-00137-4.

A. Alsadeh and N. Yatim, “A Dynamic Federated Identity Management Using OpenID Connect,” Futur. Internet, pp. 1–19, 2022.

J. Glöckler, J. Sedlmeir, M. Frank, and G. Fridgen, “A Systematic Review of Identity and Access Management Requirements in Enterprises and Potential Contributions of Self-Sovereign Identity,” Bus. Inf. Syst. Eng., vol. 66, no. 4, pp. 421–440, 2024, doi: 10.1007/s12599-023-00830-x.

T. Yogyakarta, “Comparative Analysis of the Performance of Single Sign-On Authentication Systems with OpenID and OAuth Protocols,” in International Journal of Computer and Information Technology, 2022, pp. 100–107. doi: 10.24203/ijcit.v11i3.277.

A. Zineddine, Y. Belfaik, A. Rehaimi, Y. Sadqi, and S. Safi, “Single Sign-On Security and Privacy: A Systematic Literature Review,” Comput. Mater. Contin., vol. 84, no. 3, pp. 4019–4054, 2025, doi: 10.32604/cmc.2025.066139.

A. C. Study and A. Prinz, “Applying Spring Security Framework with KeyCloak-Based OAuth2 to Protect Microservice Architecture APIs: A Case Study,” Routledge Libr. Ed. Women Crime 5 Vol. Set, vol. 5, pp. 169–171, 2022.

N. Dimitrijević, N. Zdravković, M. Bogdanović, and A. Mesterovic, “Advanced Security Mechanisms in the Spring Framework: JWT, OAuth, LDAP and Keycloak,” in CEUR Workshop Proceedings, 2024, pp. 64–70. doi: 10.35940/ijitee.F9832.059620.

B. Sousa and C. Gonçalves, “FedAAA-SDN: Federated Authentication, Authorization and Accounting in SDN controllers,” Comput. Networks, vol. 239, no. November 2023, p. 110130, 2024, doi: 10.1016/j.comnet.2023.110130.

M. Al Shabi and R. R. Marie, “Analyzing Privacy Implications and Security Vulnerabilities in Single Sign-On Systems : A Case Study on OpenID Connect,” in (IJACSA) International Journal of Advanced Computer Science and Applications, 2024, pp. 637–646.

J. Andjarwirawan, “Single Sign-On (SSO) Implementation Using Keycloak, RADIUS, LDAP, and PacketFence for Network Access,” Teknika, vol. 14, no. 1, pp. 41–46, 2025, doi: 10.34148/teknika.v14i1.1089.

S. Das, R. Priyadarshini, M. Mishra, and R. K. Barik, “Leveraging Towards Access Control, Identity Management, and Data Integrity Verification Mechanisms in Blockchain-Assisted Cloud Environments: A Comparative Study,” J. Cybersecurity Priv., vol. 4, no. 4, pp. 1018–1043, 2024, doi: 10.3390/jcp4040047.

A. H. Han and D. H. Lee, “Detecting Risky Authentication Using the OpenID Connect Token Exchange Time,” Sensors, vol. 23, no. 19, 2023, doi: 10.3390/s23198256.

P. Philippaerts, D. Preuveneers, and W. Joosen, OAuch: Exploring Security Compliance in the OAuth 2.0 Ecosystem, vol. 1, no. 1. Association for Computing Machinery, 2022. doi: 10.1145/3545948.3545955.

J. Rafael, A. Zúquete, A. Pazos, and J. Luís, “Heliyon A federated authentication schema among multiple identity providers,” Heliyon, vol. 10, no. 7, p. e28560, 2024, doi: 10.1016/j.heliyon.2024.e28560.

R. Menéndez, A. Munoz-Arcentales, J. Salvachúa, C. Aparicio, I. Plaza, and G. Huecas, “Next Generation Authentication for Data Spaces: An Authentication Flow Based on Grant Negotiation and Authorization Protocol for Verifiable Presentations (GNAP4VP),” Procedia Comput. Sci., vol. 265, pp. 226–235, 2025, doi: 10.1016/j.procs.2025.07.176.

P. N. Q. Salazar et al., “Evaluating Keycloak as an identity server versus commercial solutions in multi-platform organizational environments Evaluación de Keycloak como servidor de identidad frente a soluciones comerciales en entornos organizacionales multiplataforma,” in 5th LACCEI International Multiconference on Entrepreneurship, Innovation and Regional Development - LEIRD 2025, 2025, pp. 1–11.

A. M. Tzortzis et al., “AI4EF: Artificial Intelligence for Energy Efficiency in the building sector,” SoftwareX, vol. 30, no. April, p. 102172, 2025, doi: 10.1016/j.softx.2025.102172.

V. Morris et al., “TIMeFoRCE : An Identity and Access Management Framework for IoT Devices in A Zero Trust Architecture,” Adv. Sci. Technol. Eng. Syst. J., vol. 10, no. 6, pp. 1–22, 2025.

E. K. K. Edris, M. Aiash, M. A. Khoshkholghi, R. Naha, A. Chowdhury, and J. Loo, “Performance and cryptographic evaluation of security protocols in distributed networks using applied pi calculus and Markov Chain,” Internet of Things (Netherlands), vol. 24, no. September, p. 100913, 2023, doi: 10.1016/j.iot.2023.100913.

B. Kretarta, “Secure User Management Gateway for Microservices Architecture APIs Using Keycloak on XYZ,” in International Seminar on Research of Information Technology and Intelligent Systems (ISRITI), 2022, pp. 1–7. doi: 10.1109/ISRITI56927.2022.10052901.

E. Rushdy, W. Khedr, and N. Salah, “Framework to secure the OAuth 2.0 and JSON web token for rest API,” J. Theor. Appl. Inf. Technol., vol. 99, no. 9, pp. 2144–2161, 2021.

A. Ramaswamy, “Securing API-Based Integrations in Federated Cloud Architectures : A Zero Trust Perspective,” Eur. J. ofInformation Technol. Comput. Sci., vol. 5, no. 4, pp. 4–7, 2025.

P. Hosseyni, R. Küsters, and T. Würtele, “Formal Security Analysis of the OpenID FAPI 2.0 Family of Protocols: Accompanying a Standardization Process,” ACM Trans. Priv. Secur., vol. 28, no. 1, 2024, doi: 10.1145/3699716.

M. Kokila and S. Reddy K, “Authentication, access control and scalability models in Internet of Things Security–A review,” Cyber Secur. Appl., vol. 3, no. April 2024, p. 100057, 2025, doi: 10.1016/j.csa.2024.100057.

P. Modesti, L. Freitas, Q. Shotomiwa, and A. Almehrej, “Security analysis of the open banking account and transaction API protocol,” Cyber Secur. Appl., vol. 3, no. October 2024, p. 100097, 2025, doi: 10.1016/j.csa.2025.100097.

C. Nero, A. A. Aning, S. K. Danuor, and V. Mensah, “Prediction of compressional sonic log in the western (Tano) sedimentary basin of Ghana, West Africa using supervised machine learning algorithms,” Heliyon, vol. 9, no. 9, p. e20242, 2023, doi: 10.1016/j.heliyon.2023.e20242.


Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Nurhadi Nurhadi, Mustazzihim Suhaidi, Muhammad Athariq

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.