Techniques are provided for improving security in a single-sign-on context
by providing, to a user's client system, two linked authentication
credentials in separate logical communication sessions and requiring that
both credentials be presented to a host system. Only after presentation
of both credentials is the user authenticated and permitted to access
applications on the host system.