tech · quantum risk
Is SSO identity Quantum Proof? Cyber Program & PQC
Verdict
SSO and federated identity are not quantum-proof while assertion and token signatures remain classical. Treat IdP keys like root CA material: inventory, HSM, rotation, and algorithm roadmap.
Overview
Single sign-on concentrates authentication trust. Quantum risk includes forging classical SAML/OIDC signatures and compromising IdP TLS.
Deepen with OIDC and SAML specific pages; align with JWT quantum-risk network content.
Program inventory focus: One classical IdP signing key can mint access across the enterprise. Typical classical surfaces: SAML assertions; OIDC/JWT signatures. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
What breaks
- Decade-old IdP signing certificates
- No dual-stack plan for token algorithms
- Service providers pinned to one classical alg
FAQ
Does MFA make SSO quantum-safe?
MFA helps account takeover classically; forged tokens after IdP signature break are a different failure mode.
SPA vs SSR page?
This SSR page is the indexable educational entity; SPA hubs may still exist for UX.
Key concepts (technical dictionary)
Terms used on this page — open a definition: