Submitted:
15 June 2026
Posted:
16 June 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Materials and Methods
2.1. Study Design, Dataset, and Measurement
| Category | Group | n | % |
|---|---|---|---|
| Role | Students | 128 | 71.1% |
| Lecturers | 31 | 17.2% | |
| Administrative Staff | 21 | 11.7% | |
| Academic Unit | Graduate School (PPS) | 31 | 17.2% |
| Faculty of Mathematics and Natural Sciences (FMIPA) | 27 | 15.0% | |
| Faculty of Social Sciences (FIS) | 22 | 12.2% | |
| Faculty of Languages and Arts (FBS) | 22 | 12.2% | |
| Faculty of Economics (FE/FEB) | 19 | 10.6% | |
| Faculty of Engineering (FT) | 18 | 10.0% | |
| Faculty of Education (FIP) | 17 | 9.4% | |
| Faculty of Medicine (FK) | 12 | 6.7% | |
| Faculty of Sport Science (FIK) | 12 | 6.7% | |
| Portals Used | 3 Portals | 80 | 44.4% |
| 4 Portals | 100 | 55.6% | |
| Primary Device | Personal Laptop | 75 | 41.7% |
| Personal Smartphone | 74 | 41.1% | |
| Office / Lab Computer | 22 | 12.2% | |
| Shared Device | 9 | 5.0% | |
| Access Location | UNIMED Campus | 74 | 41.1% |
| Home / Boarding House | 73 | 40.6% | |
| School / Workplace | 25 | 13.9% | |
| Outside the City | 8 | 4.4% |
2.2. Proposed SSO Framework and Evaluation Metrics
3. Results
3.1. Authentication Performance
| Metric | Pre-SSO | Post-SSO | Change | t(179) | p | Cohen’s |
|---|---|---|---|---|---|---|
| M (SD) | M (SD) | d | ||||
| Login Time (seconds) | 48.95 (6.76) | 13.54 (3.06) | −72.3% | 64.44 | < .001 | 4.80 |
| Authentication Success Rate (%) | 83.75 (4.22) | 94.14 (2.72) | +10.39 pp | −55.19 | < .001 | 4.11 |
| Failed Logins / Month | 3.38 (1.13) | 0.85 (0.56) | −74.9% | 32.58 | < .001 | 2.43 |
| Password Resets / 3 Months | 2.23 (0.81) | 0.52 (0.50) | −76.7% | 25.57 | < .001 | 1.91 |
3.2. User Experience and System Usability Scale
| Dimension | Pre-SSO | Post-SSO | p | d | ||
|---|---|---|---|---|---|---|
| M (SD) | M (SD) | |||||
| User Experience (UX) | 3.08 (0.36) | 4.35 (0.37) | +1.27 | -78.27 | 5.83 | |
| Security Perception | 3.27 (0.32) | 4.25 (0.37) | +0.98 | -59.56 | 4.44 | |
| Overall Satisfaction | 3.04 (0.35) | 4.42 (0.39) | +1.38 | -86.14 | 6.42 |
3.3. Adaptive Authentication: Risk Distribution and Actions
4. Discussion
4.1. Interpretation of Findings in Relation to the Working Hypotheses
4.2. Comparison with Previous Studies
4.3. Theoretical and Practical Implications
4.4. Limitations
4.5. Future Research Directions
5. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Mkabe, Z. Strengthening Cybersecurity in a Government Department by Addressing Password Management Challenges and Human Factor Vulnerabilities. Discover Computing 2025, 28, 148. [CrossRef]
- Rodrigues, B.D.C.F.; Emmanuel, D.D.J.; Sharma, B.K. From RockYou to RockYou2024: Analyzing Password Patterns Across Generations, Their Use in Industrial Systems and Vulnerability to Password Guessing Attacks. Journal of Internet Services and Applications 2025, 16. [CrossRef]
- Ilboudo, A.; Bassole, D.; Kouraogo, J.P.; Koala, G.; Sie, O. Towards a Single-Sign-On Authentication Architecture Based on OpenID Connect Protocol and Blockchain Technology. In Proceedings of the Innovations and Interdisciplinary Solutions for Underserved Areas (InterSol 2024). Springer, Cham, 2025, Vol. 610, Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering. [CrossRef]
- Hosseyni, P.; Küsters, R.; Würtele, T. Formal Security Analysis of the OpenID FAPI 2.0 Family of Protocols: Accompanying a Standardization Process. ACM Transactions on Privacy and Security 2025, 28, 1–36. [CrossRef]
- Allafi, R.; Darem, A.A. Usability and Security in Online Authentication Systems. International Journal of Advanced and Applied Sciences 2025, 12, 1–12.
- Ferreras-Rodríguez, J.; Carneiro, J.; Di Nocera, F. Usable Security: A Systematic Literature Review. Information 2023, 14, 641. [CrossRef]
- Alhothaily, A.; Alrawais, A.; Song, T.; Cheng, X. Strengthening Cloud Security: An Innovative Multi-Factor Multi-Layer Authentication Framework for Cloud User Authentication. Applied Sciences 2023, 13, 10871. [CrossRef]
- Kowalski, M.; Hüffmeyer, M.; Schwittay, S. Challenges and Potential Improvements for Passkey Adoption—A Literature Review with a User-Centric Perspective. Applied Sciences 2025, 15, 4414. [CrossRef]
- Hevner, A.R.; Parsons, J.; Brendel, A.B.; Lukyanenko, R.; Tiefenbeck, V.; Tremblay, M.C.; vom Brocke, J. Transparency in Design Science Research. Decision Support Systems 2024, 182, 114236. [CrossRef]
- Durity, A.L.; et al. Measuring NIST Authentication Standards Compliance by Higher Education Institutions, 2024, [2409.00546].
- Sakimura, N.; Bradley, J.; Jones, M.B.; de Medeiros, B.; Mortimore, C. OpenID Connect Core 1.0 Incorporating Errata Set 2. Technical report, OpenID Foundation, 2023. OpenID Connect Core Specification.
- Ilboudo, A.; Bassole, D.; Kouraogo, J.P.; Koala, G.; Sie, O. Towards a Single-Sign-On Authentication Architecture Based on OpenID Connect Protocol and Blockchain Technology. In Proceedings of the Innovations and Interdisciplinary Solutions for Underserved Areas (InterSol 2024), Cham, 2025; Vol. 610, Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, pp. 87–99. [CrossRef]
- Fugkeaw, S. Achieving Decentralized and Dynamic SSO-Identity Access Management System for Multi-Application Outsourced in Cloud. IEEE Access 2023, 11, 25480–25491. [CrossRef]
- Cohen, J. Statistical Power Analysis for the Behavioral Sciences, 2nd ed.; Lawrence Erlbaum Associates: Hillsdale, NJ, 1988.
- Wiefling, S.; Jørgensen, P.R.; Thunem, S.; Lo Iacono, L. Pump Up Password Security! Evaluating and Enhancing Risk-Based Authentication on a Real-World Large-Scale Online Service. ACM Transactions on Privacy and Security 2023, 26, 1–36. [CrossRef]
- Wiefling, S.; Dürmuth, M.; Lo Iacono, L. More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based Authentication. In Proceedings of the Annual Computer Security Applications Conference (ACSAC ’20). ACM, 2020. [CrossRef]
- Murti, Y.R.; Afgani, F.A.; Rijanandi, T. Towards an Integrated Authentication System: Single Sign-On (SSO) Architecture for Higher Education Applications. COELITE: Journal of Computer Engineering, Information and Technology 2024.
- Hastings, S.; Moore, T.; Gandal, N. Quantifying Costs of Enhanced Security in Multifactor Authentication. Information Systems Frontiers 2025. [CrossRef]
- Schorr, A. The Technology Acceptance Model (TAM) and its Importance for Digitalization Research: A Review. Journal of Applied Research in Higher Education 2023. Open Access, CC BY-NC-ND 4.0.
- Hosseyni, P.; Küsters, R.; Würtele, T. Formal Security Analysis of the OpenID FAPI 2.0 Family of Protocols: Accompanying a Standardization Process. ACM Transactions on Privacy and Security 2024, 28, 1–36. [CrossRef]



| Role | n | Pre-SSO SUS | Post-SSO SUS | Improv. | Post-SSO |
|---|---|---|---|---|---|
| M (SD) | M (SD) | Category | |||
| Students | 128 | 65.8 (4.5) | 85.9 (4.2) | +20.1 | Excellent |
| Lecturers | 31 | 68.0 (5.4) | 86.6 (4.4) | +18.6 | Excellent |
| Administrative Staff | 21 | 65.7 (2.7) | 85.8 (3.5) | +20.1 | Excellent |
| Overall | 180 | 66.21 (4.58) | 85.99 (4.12) | +19.78 | Excellent |
| Risk Level | Direct Access | Light OTP | Device Verif. | Admin Review | Total |
|---|---|---|---|---|---|
| Low | 106 | 10 | 0 | 0 | 116 |
| Medium | 11 | 27 | 10 | 0 | 48 |
| High | 0 | 5 | 6 | 5 | 16 |
| Total | 117 | 42 | 16 | 5 | 180 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).