Performance benchmark 3.29

Prev Next

This topic provides empirical performance benchmark data, hardware sizing baselines, and deployment topology recommendations for OneSpan Authentication Server 3.29. The figures herein reflect measurements conducted across supported database management systems (MariaDB and Oracle Database) deployed in containerized Kubernetes environments running on modern Linux operating systems.

Test environment and system specifications

Hardware and cluster infrastructure

  • Kubernetes nodes: Dedicated multi-core performance worker nodes, with different pod/vCPU configurations

  • Database host sizing: Tested across 2, 4, 6, and 8 vCPUs (4 vCPUs identified as the baseline production recommendation)

Software environment and versions

  • Operating system: Ubuntu 24.04 LTS (64-bit)

  • Application versions: OneSpan Authentication Server 3.29.1

  • Database systems:

    • MariaDB: MariaDB 11.8 LTS

    • Oracle Database: Oracle 19c Enterprise Edition

  • Directory services: OpenLDAP

Test automation

The performance results were gathered by running JMeter test suites and automatically collecting container CPU and memory telemetry .

Test scenarios and workload profiles

Performance measurements were gathered against a benchmark population of 30,000 users across different workload profiles, running test cases for 120s average with 10, 50, and 100 concurrent threads.

The scope included to collect overall latency and throughput for different configurations, analyze bottlenecks, and identify optimal pod/CPU ratio and saturation limits.

Performance benchmark results

The following tables summarize average response times and 90th percentile (P90) response times under maximum throughput conditions. All response times are measured in milliseconds (ms).

Authentication operations response times (ms)

Scenario/operation

MariaDB 11.8

Average / P90 (ms)

Oracle 19c

Average / P90 (ms)

Difference

AuthUser static password (No authenticator)

30 / 44

43 / 59

MariaDB ~30% faster

AuthUser static password (1 authenticator)

45 / 67

48 / 71

MariaDB ~6% faster

AuthUser OTP validation

41 / 66

64 / 90

MariaDB ~36% faster

SOAP administrative operations response times (ms)

Operation

MariaDB 11.8

Average/P90 (ms)

Oracle 19c

Average/P90 (ms)

Difference

Administrative logon

32 / 23

115 / 45

MariaDB ~72% faster

Administrative logoff

3 / 3

10 / 9

MariaDB ~70% faster

User View operation

29 / 42

41 / 56

MariaDB ~29% faster

Digipass View operation

24 / 36

44 / 56

MariaDB ~46% faster

Configuration update

7 / 7

25 / 25

MariaDB ~72% faster

Create client component

10 / 10

28 / 28

MariaDB ~ 64% faster

Check ImportDPX task status

5  / 5

11 / 13

MariaDB ~55% faster

Throughput and maximum capacity (transactions/second)

Workload type

MariaDB 11.8

Oracle 19c

Authentication throughput (Peak)

~400 trans/sec

(2 vCPU DB)

~200 trans/sec

(4 vCPU DB)

Webadmin provisioning

>300 trans/sec

~20 trans/sec

Standard user provisioning

~150 trans/sec

~100 trans/sec

User provisioning with multiple authenticators

~100 trans/sec

~80 trans/sec

Deployment sizing & recommendations

Database sizing

  • Baseline allocation. 4 vCPUs provides the optimal price-to-performance ratio for standard deployments.

  • Scaling ceiling. Increasing database allocation from 4 vCPUs to 8 vCPUs on a standard 2-pod OAS setup yields marginal throughput gains (<5%), as application connection limits become the constraining factor before CPU exhaustion.

Kubernetes pod vs. CPU allocation

When planning container resources for OAS/IAS instances:

  • Proxy overhead. A single pod with 2 CPUs achieves higher efficiency and lower latency than 2 pods with 1 CPU each, mainly due to multi-pod network proxy overhead.

  • Optimal production ratio. The recommended baseline configuration for both DBMS is 2 pods with 5 CPUs each. It maximizes balance of throughput, response time, and stability.

    • MariaDB outperforms Oracle in throughput (~2x), response time (~40% faster), and error rate.

    • 10 Pods with 1 CPU each is worst for both. Network overhead between pods dominates.

    • 1 Pod with 10 CPU offers diminishing returns. This is only marginally slower than 2 pods for both DBMS.

    • 5 Pods with 2 CPUs underperforms. Network overhead is already significant at this ratio.

  • Cluster saturation limits (4 vCPU DBMS)

    • Oracle 19c: Database CPU reaches 100% saturation at 5 OAS pods under heavy concurrent load (50+ threads).

    • MariaDB: Database saturation occurs at 5 to 6 OAS pods under heavy concurrent load.

Performance regression testing was conducted across both MariaDB and Oracle 19c environments to evaluate latency, throughput, and stability differences between OneSpan Authentication Server 3.28.1 (baseline) and OneSpan Authentication Server 3.29.1 under identical 30,000-user load workloads.

Note that MariaDB was upgraded from version 10.11 LTS in OAS 3.28 to 11.8 LTS in OAS 3.29.

Benchmark comparison by operation (Average response time, in ms)

Scenario/operation

OAS 3.28.1

OAS 3.29.1

Difference

MariaDB

AuthUser OTP validation

44

38

–15.8%

AuthUser static password (No authenticator)

32

31

–3.2%

AuthUser static password (1 authenticator)

47

43

–9.3%

Digipass View operation

24

24

±0%

User View operation

30

29

–3.4%

Oracle Database

AuthUser OTP validation

62

62

±0%

AuthUser static password (No authenticator)

39

37

–5.4%

AuthUser static password (1 authenticator)

50

48

–4.2%

DP View operation

31

29

–6.9%

User View operation

35

33

–6.1%

Key results

  • Optimized OTP processing (MariaDB). Version 3.29.1 introduces measurable latency improvements in Digipass OTP validation workflows when using MariaDB, dropping average response times from 44 ms down to 38 ms.

  • Engine stability across minor releases. Read/view operations and static password authentications show consistent execution timings across both releases, indicating no regressions in query performance or indexing overhead.

  • Oracle 19c parity. Oracle 19c exhibits near-identical response time profiles between 3.28.1 and 3.29.1 across all standard authentication paths, maintaining predictable throughput characteristics.