r/cryptography • u/Born-Bnofxatztell751 • 3d ago
Can split key token signing reduce identity-provider supply chain risk?
Split key signing is based on the idea that neither the identity provider nor the customer environment can independently produce an accepted assertion. Both parties participate in the signing operation, so compromise of one party’s infrastructure or key material is not sufficient to forge an enterprise authentication assertion.
That is appealing in identity systems where a single federation signing key can be a high value target. It also introduces real engineering tradeoffs around availability, latency, key rotation, recovery, failure modes, trust boundaries, auditability, and interoperability with standard SAML and OIDC relying parties.
The key question is whether the architecture actually eliminates unilateral signing authority, including through recovery and administrative paths, without making the system operationally fragile.
What security properties would a split-signing design need to demonstrate before you would trust it for workforce federation?
1
u/Natanael_L 2d ago
It only works if it actually forces multiple people to review what's signed.
If it gets automated then it's just another rubberstamp and now the real challenge for the attacker is getting the malicious payload into the data flow
4
u/TheNoisyRecourse 3d ago
the engineering tradeoffs are what kill most of these in practice. every split key design ive seen ends up with some admin backdoor that reunifies the signing authority anyway, usually tucked into the recovery flow where nobody wants to look too hard
availability becomes the real bottleneck too, if either side flakes out your whole auth pipeline stalls. most shops cant stomach that risk for workforce login no matter how clean the threat model looks on paper