Faculty of Computing-Scopus
Permanent URI for this collectionhttps://rda.sliit.lk/handle/123456789/4892
Browse
Now showing 1 - 1 of 1
- Results Per Page
- Sort Options
Item Embargo Secure Enhanced JWT Framework with Post-Quantum Cryptography(Institute of Electrical and Electronics Engineers Inc., 2026-05-22) Sunera, A; Ransika, Y; Rasiru, M; Gunawardane, A; Abeywardena, K. Y; Senarathne, AJSON Web Tokens (JWTs) are widely used in distributed authentication, but many implementations still rely on classical algorithms such as RSA and provide limited support for key transparency, guarded validation, and secure revocation. These limitations reduce their suitability for future-ready security environments [1], [2], [3]. This research proposes a secure enhanced JWT framework built on four integrated components: a post-quantum signing and verification service, a transparency-driven key distribution service, a guard layer for policy enforcement, and a secure revocation service. The framework introduces ML-DSA-based post-quantum signatures while strengthening key integrity, token validation, and revocation control. A classical RS256-based authentication system was used as the baseline and compared against the integrated post-quantum system. The baseline recorded an average login latency of 77.891 ms, verification latency of 17.078 ms, protected endpoint latency of 14.608 ms, and an average token size of 519 bytes. The integrated post-quantum system achieved an overall average request latency of 67.245 ms, 97.667 ms p95 request latency, zero request failures, and 71.943 requests per second in the scoped live benchmark. The results show that the proposed framework maintains operational stability while delivering stronger security properties than conventional JWT systems, contributing a unified JWT security architecture that integrates post-quantum signatures, transparency-based key distribution, guarded validation, and revocation-aware trust enforcement into a single end-to-end authentication model.
