Electrotechnical and Computer Engineering
Vol. 41 No. 08 (2026): Proceedings of the Faculty of Technical Sciences
Session and Token Based Authentication and Authorization for Legacy Information Systems
Abstract
This thesis presents the integration of OAuth 2.0 and OpenID Connect into legacy session-based applications, using AWS Cognito for user and token management. The proposed hybrid model, supported by a .NET proof of concept, describes the system architecture, token verification and revocation, and session creation, enabling a gradual migration to cloud standards without full system reconstruction.
References
- [1] Sam Newman. Building Microservices (2nd ed.).
- O’Reilly Media, 2021.
- [2] RFC 9700 (BCP 240): OAuth 2.0 Security Best
- Current Practice, 2025.
- [5] Fett, D., Küsters, R., Schmitz, G. A Comprehensive
- Formal Security Analysis of OAuth 2.0.
- [6] Richer, J., Sanso, A. OAuth 2 in Action. Manning
- Publications, 2017.
- [7] Madden, N. API Security in Action. Manning
- Publications, 2020.
- [8] Siriwardena, P., Dias, N. Microservices Security in
- Action. Manning Publications, 2020.
- [9] RFC 7519 — JSON Web Token (JWT), IETF, 2015.
- [10] Michael Wittig, Andreas Wittig. Amazon Web
- Services in Action (3rd ed.). Manning Publications,
- 2023.
- [11] Mark J. Price. C# 12 and .NET 8 – Modern
- Cross-Platform Development. Packt, 2024.