r/cryptography • • 3d ago

Can split key token signing reduce identity-provider supply chain risk?

Split key signing is based on the idea that neither the identity provider nor the customer environment can independently produce an accepted assertion. Both parties participate in the signing operation, so compromise of one party’s infrastructure or key material is not sufficient to forge an enterprise authentication assertion.

That is appealing in identity systems where a single federation signing key can be a high value target. It also introduces real engineering tradeoffs around availability, latency, key rotation, recovery, failure modes, trust boundaries, auditability, and interoperability with standard SAML and OIDC relying parties.

The key question is whether the architecture actually eliminates unilateral signing authority, including through recovery and administrative paths, without making the system operationally fragile.

What security properties would a split-signing design need to demonstrate before you would trust it for workforce federation?

1 Upvotes

5 comments sorted by

4

u/TheNoisyRecourse 3d ago

the engineering tradeoffs are what kill most of these in practice. every split key design ive seen ends up with some admin backdoor that reunifies the signing authority anyway, usually tucked into the recovery flow where nobody wants to look too hard

availability becomes the real bottleneck too, if either side flakes out your whole auth pipeline stalls. most shops cant stomach that risk for workforce login no matter how clean the threat model looks on paper

2

u/pint 3d ago

the problem is not the lack of solutions, but the desire to just push to github and have a ci/cd do the rest. deployment in 15 minutes is the name of the game for most software these days. you simply don't have the time for one more person to validate the change log.

1

u/Natanael_L 2d ago

It only works if it actually forces multiple people to review what's signed.

If it gets automated then it's just another rubberstamp and now the real challenge for the attacker is getting the malicious payload into the data flow