MULTI-FACTOR AUTHENTICATION, SINGLE SIGN-ON, AND IDENTITY MANAGEMENT IN CLOUD-BASED HEALTHCARE MOBILE APPLICATIONS A Reference Architecture and STRIDE Threat-Model Evaluation
Abstract
Healthcare mobile applications increasingly expose scheduling, messaging, billing, medication, and clinical-information services through cloud APIs. This creates an identity boundary that must resist credential theft, token interception, session replay, privilege misuse, and fragmented account governance without imposing excessive friction on patients and clinicians. This study develops and evaluates a standards-based reference architecture integrating single sign-on (SSO), multi-factor authentication (MFA), federated identity, lifecycle governance, server-side authorization, and auditable policy enforcement. The design is synthesized from NIST Digital Identity Guidelines, OAuth 2.0 and OpenID Connect standards, HIPAA Security Rule requirements, CISA guidance, and the OWASP Mobile Application Security Verification Standard. A structured STRIDE threat model is applied to ten representative attack scenarios. Each scenario is assessed using ordinal likelihood and impact scales before and after proposed controls. The evaluation indicates that no single mechanism is sufficient: SSO centralizes enforcement but also concentrates risk; MFA improves assurance but remains vulnerable when implemented with phishable factors; and mobile