← Back to problems

16. Session Store and Auth Service

MEDIUM
AuthenticationRate LimiterSecuritySession ManagementSystem Design

Design an authentication service that validates credentials, issues sessions, and validates a session token on every subsequent request at high volume, while resisting credential-stuffing attacks.

Design an authentication and session service. Users log in with credentials; on success the service issues a session token. Every subsequent request to the wider product carries that token and must be validated : so session lookup is on the hot path of essentially all authenticated traffic, far more frequent than logins themselves. Sessions are ephemeral, keyed by token, and must be read with very low latency on every request; they are not long-term records of account. The login path, by contrast, is a security-sensitive write path: it must resist credential-stuffing and brute-force attacks, where an attacker tries many credentials across many accounts, so login attempts must be rate-limited per client/account. Design the architecture: how logins are validated and rate-limited, where session state lives so that token validation is fast and shared across all serving instances, and where durable account records are stored. Then document the API, the security model, and the trade-offs of session storage choices.
Log in to submit a solution

Comments

Log into join the discussion.