Post-Quantum Cryptography for Web Authentication Protocols: A Systematic Review of OAuth 2.0, OpenID Connect, and SAML Migration
| dc.contributor.author | Dissanayake, R | |
| dc.contributor.author | Wijesinghe, H | |
| dc.contributor.author | Vindinu, J | |
| dc.contributor.author | Jayasinghe, K | |
| dc.contributor.author | Abeywardena, K | |
| dc.contributor.author | Senarathne, A | |
| dc.date.accessioned | 2026-05-25T06:59:10Z | |
| dc.date.issued | 2026-03-19 | |
| dc.description.abstract | OAuth 2.0, OpenID Connect (OIDC), and SAML rely on classical public-key primitives such as RSA and ECDSA, which are vulnerable to quantum attacks via Shor's algorithm. This systematic review examines migration of these protocols to Post-Quantum Cryptography (PQC) following the 2024 NIST standardization of ML-DSA and ML-KEM. We map cryptographic dependencies across all three protocols, evaluate NIST-standardized algorithms for authentication use cases, and analyze practical migration challenges. Token size explosion, with ML-DSA-65 signatures approximately 52 times larger than ECDSA P-256, represents the dominant implementation barrier, compounded by incomplete JOSE standardization and limited ecosystem maturity. Missing formal security proofs and federation migration frameworks are identified as critical priorities before production deployment. | |
| dc.identifier.doi | DOI: 10.1109/ISDFS69419.2026.11459000 | |
| dc.identifier.issn | 27681831 | |
| dc.identifier.uri | https://rda.sliit.lk/handle/123456789/5052 | |
| dc.language.iso | en | |
| dc.publisher | Institute of Electrical and Electronics Engineers Inc. | |
| dc.relation.ispartofseries | Proceedings of the International Symposium on Digital Forensics and Security, ISDFS | |
| dc.subject | Web Authentication | |
| dc.subject | Post-Quantum Cryptography | |
| dc.subject | SAML | |
| dc.subject | OpenID Connect | |
| dc.subject | OAuth 2.0 | |
| dc.subject | ML-KEM | |
| dc.subject | ML-DSA | |
| dc.title | Post-Quantum Cryptography for Web Authentication Protocols: A Systematic Review of OAuth 2.0, OpenID Connect, and SAML Migration | |
| dc.type | Article |
Files
Original bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- Post-Quantum_Cryptography_for_Web_Authentication_Protocols_A_Systematic_Review_of_OAuth_2.0_OpenID_Connect_and_SAML_Migration.pdf
- Size:
- 359.33 KB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 1.69 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
