Skip to main navigation menu Skip to main content Skip to site footer

Electrotechnical and Computer Engineering

Vol. 41 No. 08 (2026): Proceedings of the Faculty of Technical Sciences

Session and Token Based Authentication and Authorization for Legacy Information Systems

  • Zivko Stanisic
DOI:
https://doi.org/10.24867/
Submitted
September 7, 2026
Published
2026-09-09

Abstract

This thesis presents the integration of OAuth 2.0 and OpenID Connect into legacy session-based applications, using AWS Cognito for user and token management. The proposed hybrid model, supported by a .NET proof of concept, describes the system architecture, token verification and revocation, and session creation, enabling a gradual migration to cloud standards without full system reconstruction. 

References

  1. [1] Sam Newman. Building Microservices (2nd ed.).
  2. O’Reilly Media, 2021.
  3. [2] RFC 9700 (BCP 240): OAuth 2.0 Security Best
  4. Current Practice, 2025.
  5. [5] Fett, D., Küsters, R., Schmitz, G. A Comprehensive
  6. Formal Security Analysis of OAuth 2.0.
  7. [6] Richer, J., Sanso, A. OAuth 2 in Action. Manning
  8. Publications, 2017.
  9. [7] Madden, N. API Security in Action. Manning
  10. Publications, 2020.
  11. [8] Siriwardena, P., Dias, N. Microservices Security in
  12. Action. Manning Publications, 2020.
  13. [9] RFC 7519 — JSON Web Token (JWT), IETF, 2015.
  14. [10] Michael Wittig, Andreas Wittig. Amazon Web
  15. Services in Action (3rd ed.). Manning Publications,
  16. 2023.
  17. [11] Mark J. Price. C# 12 and .NET 8 – Modern
  18. Cross-Platform Development. Packt, 2024.