This topic provides empirical performance benchmark data, hardware sizing baselines, and deployment topology recommendations for OneSpan Authentication Server 3.29. The figures herein reflect measurements conducted across supported database management systems (MariaDB and Oracle Database) deployed in containerized Kubernetes environments running on modern Linux operating systems.
Test environment and system specifications
Hardware and cluster infrastructure
Kubernetes nodes: Dedicated multi-core performance worker nodes, with different pod/vCPU configurations
Database host sizing: Tested across 2, 4, 6, and 8 vCPUs (4 vCPUs identified as the baseline production recommendation)
Software environment and versions
Operating system: Ubuntu 24.04 LTS (64-bit)
Application versions: OneSpan Authentication Server 3.29.1
Database systems:
MariaDB: MariaDB 11.8 LTS
Oracle Database: Oracle 19c Enterprise Edition
Directory services: OpenLDAP
Test automation
The performance results were gathered by running JMeter test suites and automatically collecting container CPU and memory telemetry .
Test scenarios and workload profiles
Performance measurements were gathered against a benchmark population of 30,000 users across different workload profiles, running test cases for 120s average with 10, 50, and 100 concurrent threads.
The scope included to collect overall latency and throughput for different configurations, analyze bottlenecks, and identify optimal pod/CPU ratio and saturation limits.
Performance benchmark results
The following tables summarize average response times and 90th percentile (P90) response times under maximum throughput conditions. All response times are measured in milliseconds (ms).
Authentication operations response times (ms)
Scenario/operation | MariaDB 11.8 Average / P90 (ms) | Oracle 19c Average / P90 (ms) | Difference |
|---|---|---|---|
AuthUser static password (No authenticator) | 30 / 44 | 43 / 59 | MariaDB ~30% faster |
AuthUser static password (1 authenticator) | 45 / 67 | 48 / 71 | MariaDB ~6% faster |
AuthUser OTP validation | 41 / 66 | 64 / 90 | MariaDB ~36% faster |
SOAP administrative operations response times (ms)
Operation | MariaDB 11.8 Average/P90 (ms) | Oracle 19c Average/P90 (ms) | Difference |
|---|---|---|---|
Administrative logon | 32 / 23 | 115 / 45 | MariaDB ~72% faster |
Administrative logoff | 3 / 3 | 10 / 9 | MariaDB ~70% faster |
User View operation | 29 / 42 | 41 / 56 | MariaDB ~29% faster |
Digipass View operation | 24 / 36 | 44 / 56 | MariaDB ~46% faster |
Configuration update | 7 / 7 | 25 / 25 | MariaDB ~72% faster |
Create client component | 10 / 10 | 28 / 28 | MariaDB ~ 64% faster |
Check ImportDPX task status | 5 / 5 | 11 / 13 | MariaDB ~55% faster |
Throughput and maximum capacity (transactions/second)
Workload type | MariaDB 11.8 | Oracle 19c |
|---|---|---|
Authentication throughput (Peak) | ~400 trans/sec (2 vCPU DB) | ~200 trans/sec (4 vCPU DB) |
Webadmin provisioning | >300 trans/sec | ~20 trans/sec |
Standard user provisioning | ~150 trans/sec | ~100 trans/sec |
User provisioning with multiple authenticators | ~100 trans/sec | ~80 trans/sec |
Deployment sizing & recommendations
Database sizing
Baseline allocation. 4 vCPUs provides the optimal price-to-performance ratio for standard deployments.
Scaling ceiling. Increasing database allocation from 4 vCPUs to 8 vCPUs on a standard 2-pod OAS setup yields marginal throughput gains (<5%), as application connection limits become the constraining factor before CPU exhaustion.
Kubernetes pod vs. CPU allocation
When planning container resources for OAS/IAS instances:
Proxy overhead. A single pod with 2 CPUs achieves higher efficiency and lower latency than 2 pods with 1 CPU each, mainly due to multi-pod network proxy overhead.
Optimal production ratio. The recommended baseline configuration for both DBMS is 2 pods with 5 CPUs each. It maximizes balance of throughput, response time, and stability.
MariaDB outperforms Oracle in throughput (~2x), response time (~40% faster), and error rate.
10 Pods with 1 CPU each is worst for both. Network overhead between pods dominates.
1 Pod with 10 CPU offers diminishing returns. This is only marginally slower than 2 pods for both DBMS.
5 Pods with 2 CPUs underperforms. Network overhead is already significant at this ratio.
Cluster saturation limits (4 vCPU DBMS)
Oracle 19c: Database CPU reaches 100% saturation at 5 OAS pods under heavy concurrent load (50+ threads).
MariaDB: Database saturation occurs at 5 to 6 OAS pods under heavy concurrent load.
Version comparison: 3.28.1 vs. 3.29.1
Performance regression testing was conducted across both MariaDB and Oracle 19c environments to evaluate latency, throughput, and stability differences between OneSpan Authentication Server 3.28.1 (baseline) and OneSpan Authentication Server 3.29.1 under identical 30,000-user load workloads.
Note that MariaDB was upgraded from version 10.11 LTS in OAS 3.28 to 11.8 LTS in OAS 3.29.
Benchmark comparison by operation (Average response time, in ms)
Scenario/operation | OAS 3.28.1 | OAS 3.29.1 | Difference |
|---|---|---|---|
MariaDB | |||
AuthUser OTP validation | 44 | 38 | –15.8% |
AuthUser static password (No authenticator) | 32 | 31 | –3.2% |
AuthUser static password (1 authenticator) | 47 | 43 | –9.3% |
Digipass View operation | 24 | 24 | ±0% |
User View operation | 30 | 29 | –3.4% |
Oracle Database | |||
AuthUser OTP validation | 62 | 62 | ±0% |
AuthUser static password (No authenticator) | 39 | 37 | –5.4% |
AuthUser static password (1 authenticator) | 50 | 48 | –4.2% |
DP View operation | 31 | 29 | –6.9% |
User View operation | 35 | 33 | –6.1% |
Key results
Optimized OTP processing (MariaDB). Version 3.29.1 introduces measurable latency improvements in Digipass OTP validation workflows when using MariaDB, dropping average response times from 44 ms down to 38 ms.
Engine stability across minor releases. Read/view operations and static password authentications show consistent execution timings across both releases, indicating no regressions in query performance or indexing overhead.
Oracle 19c parity. Oracle 19c exhibits near-identical response time profiles between 3.28.1 and 3.29.1 across all standard authentication paths, maintaining predictable throughput characteristics.